DMS MongoDB エンドポイント設定の平文パスワード

DMS の MongoDB 接続用パスワードをテンプレートやパラメータの既定値に含めないでください。

説明

CloudFormation の AWS::DMS::Endpoint で MongoDbSettings.Password を直接記述したり、パラメータの Default に保存したりすると、MongoDB ソースエンドポイントの認証情報がテンプレートや履歴に残ります。

想定される影響

データベースに接続できる人がパスワードを取得すると、移行用アカウントの権限でソースデータにアクセスするおそれがあります。

対処方法

既定値を設定せずにパスワードを安全に渡すか、DMS と Secrets Manager の連携を利用してください。パスワードのパラメータには NoEcho: true を設定し、値をログや出力に残さないでください。露出したパスワードは MongoDB で変更し、DMS の接続情報も更新して接続を確認してください。

例

MongoDB ソースエンドポイントのサーバーとユーザー名を指定します。変更前の既定値は例示用のパスワードです。変更後は、既存の MongoDB アカウントのパスワードを MasterMongoDBPassword に安全に渡します。エンドポイントの設定では、データベースアカウント自体のパスワードは変更されません。

変更前

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  MongoDBServer:
    Type: String
  ParentMasterUsername:
    Type: String
  MasterMongoDBPassword:
    Type: String
    Default: "as@3djdkDjskjs73!!"
Resources:
  NewAmpApp1:
    Type: AWS::DMS::Endpoint
    Properties:
      EngineName: mongodb
      EndpointType: source
      SslMode: require
      MongoDbSettings:
        AuthType: password
        AuthSource: admin
        Password: !Ref MasterMongoDBPassword
        Port: 27017
        ServerName: !Ref MongoDBServer
        Username: !Ref ParentMasterUsername

変更後

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  MongoDBServer:
    Type: String
  ParentMasterUsername:
    Type: String
  MasterMongoDBPassword:
    Type: String
    NoEcho: true
Resources:
  NewAmpApp1:
    Type: AWS::DMS::Endpoint
    Properties:
      EngineName: mongodb
      EndpointType: source
      SslMode: require
      MongoDbSettings:
        AuthType: password
        AuthSource: admin
        Password: !Ref MasterMongoDBPassword
        Port: 27017
        ServerName: !Ref MongoDBServer
        Username: !Ref ParentMasterUsername

参考資料