説明
CloudFormation の AWS::DMS::Endpoint で MongoDbSettings.Password を直接記述したり、パラメータの Default に保存したりすると、MongoDB ソースエンドポイントの認証情報がテンプレートや履歴に残ります。
想定される影響
データベースに接続できる人がパスワードを取得すると、移行用アカウントの権限でソースデータにアクセスするおそれがあります。
対処方法
既定値を設定せずにパスワードを安全に渡すか、DMS と Secrets Manager の連携を利用してください。パスワードのパラメータには NoEcho: true を設定し、値をログや出力に残さないでください。露出したパスワードは MongoDB で変更し、DMS の接続情報も更新して接続を確認してください。
例
MongoDB ソースエンドポイントのサーバーとユーザー名を指定します。変更前の既定値は例示用のパスワードです。変更後は、既存の MongoDB アカウントのパスワードを MasterMongoDBPassword に安全に渡します。エンドポイントの設定では、データベースアカウント自体のパスワードは変更されません。
変更前
yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
MongoDBServer:
Type: String
ParentMasterUsername:
Type: String
MasterMongoDBPassword:
Type: String
Default: "as@3djdkDjskjs73!!"
Resources:
NewAmpApp1:
Type: AWS::DMS::Endpoint
Properties:
EngineName: mongodb
EndpointType: source
SslMode: require
MongoDbSettings:
AuthType: password
AuthSource: admin
Password: !Ref MasterMongoDBPassword
Port: 27017
ServerName: !Ref MongoDBServer
Username: !Ref ParentMasterUsername
変更後
yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
MongoDBServer:
Type: String
ParentMasterUsername:
Type: String
MasterMongoDBPassword:
Type: String
NoEcho: true
Resources:
NewAmpApp1:
Type: AWS::DMS::Endpoint
Properties:
EngineName: mongodb
EndpointType: source
SslMode: require
MongoDbSettings:
AuthType: password
AuthSource: admin
Password: !Ref MasterMongoDBPassword
Port: 27017
ServerName: !Ref MongoDBServer
Username: !Ref ParentMasterUsername