DocumentDB クラスターの平文マスターパスワード

DocumentDB のマスターパスワードをテンプレートやパラメータの既定値に含めないでください。

説明

CloudFormation の AWS::DocDB::DBCluster で MasterUserPassword を直接記述したり、パラメータの Default に保存したりすると、マスターアカウントのパスワードがテンプレートやリポジトリの履歴に残ります。

想定される影響

クラスターに接続できる人がパスワードを取得すると、マスターアカウントの権限でデータを読み取り、変更、削除するおそれがあります。

対処方法

既定値を設定せずにパスワードを安全に渡すか、Secrets Manager を使った DocumentDB のパスワード管理を利用してください。パスワードのパラメータには NoEcho: true を指定し、値を出力やログに残さないでください。露出したパスワードはクラスター側で変更し、アプリケーションの接続用認証情報も更新してください。

例

新規クラスターへの認証情報の渡し方を比較する例です。既存のサブネットグループと対応するエンジンバージョンを指定し、DB インスタンスとアクセス制御は別途設定します。変更後のパスワードは 8~100 文字の印字可能な ASCII 文字で指定します。/、"、@ は使用できません。変更前のパスワードは例示用です。

変更前

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  DBSubnetGroupName:
    Type: String
  EngineVersion:
    Type: String
Resources:
  NewAmpApp:
    Type: AWS::DocDB::DBCluster
    Properties:
      BackupRetentionPeriod: 8
      DBClusterIdentifier: sample-cluster
      DBSubnetGroupName: !Ref DBSubnetGroupName
      EngineVersion: !Ref EngineVersion
      DeletionProtection: true
      MasterUsername: docdbadmin
      MasterUserPassword: "asDjskjs73!!"
      Port: 27017
      PreferredBackupWindow: 07:34-08:04
      PreferredMaintenanceWindow: sat:04:51-sat:05:21
      StorageEncrypted: true

変更後

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  ParentMasterPassword:
    Type: String
    NoEcho: true
    MinLength: 8
    MaxLength: 100
  DBSubnetGroupName:
    Type: String
  EngineVersion:
    Type: String
Resources:
  NewAmpApp:
    Type: AWS::DocDB::DBCluster
    Properties:
      BackupRetentionPeriod: 8
      DBClusterIdentifier: sample-cluster
      DBSubnetGroupName: !Ref DBSubnetGroupName
      EngineVersion: !Ref EngineVersion
      DeletionProtection: true
      MasterUsername: docdbadmin
      MasterUserPassword: !Ref ParentMasterPassword
      Port: 27017
      PreferredBackupWindow: 07:34-08:04
      PreferredMaintenanceWindow: sat:04:51-sat:05:21
      StorageEncrypted: true

参考資料