Description
An overly broad principal or action grant in a Secrets Manager resource policy can permit unnecessary access to passwords, tokens and API keys. Separate secret retrieval from management operations such as changes and deletion, and allow only required roles.
Actual access also depends on policy conditions, other permission controls and required KMS permissions. Resource: "*" in a resource policy attached to a secret refers to that secret; this value alone does not grant access to every secret in the account.
Potential impact
- Unnecessary retrieval permissions can expose secrets and affect connected databases or other services.
- Excessive modification or deletion permissions can cause outages or authentication failures in consuming services.
Remediation
- Limit Principal to approved roles and allow only the operations needed for retrieval, rotation or administration.
- Review the resource policy with IAM and KMS permissions and configure the required access conditions.
- Verify intended use and rejection of unapproved access. If a secret was exposed, rotate it and update the services that use it.
Examples
These excerpts narrow the resource policy for the same secret. Replace the role ARN with an approved role. Configure secret-value storage and required KMS permissions separately.
Before
resource "aws_secretsmanager_secret" "app_secret" {
name = "not_secure_secret"
}
resource "aws_secretsmanager_secret_policy" "app_secret_policy" {
secret_arn = aws_secretsmanager_secret.app_secret.arn
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "*"
},
"Action": "secretsmanager:*",
"Resource": "*"
}
]
}
POLICY
}
This permits secretsmanager:* for all AWS principals. Review the other controls that apply and remove unnecessary grants.
After
resource "aws_secretsmanager_secret" "app_secret" {
name = "not_secure_secret"
}
resource "aws_secretsmanager_secret_policy" "app_secret_policy" {
secret_arn = aws_secretsmanager_secret.app_secret.arn
policy = <<POLICY
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::123456789012:role/app-runtime"
},
"Action": "secretsmanager:GetSecretValue",
"Resource": "*"
}
]
}
POLICY
}
This permits only GetSecretValue for the specified role on the same secret. Also review permissions outside this policy and access to the key.