평문 비밀번호가 포함된 DMS MongoDB 엔드포인트 설정

DMS MongoDB 접속 비밀번호를 템플릿과 파라미터 기본값에서 분리하세요.

설명

CloudFormation의 AWS::DMS::Endpoint에서 MongoDbSettings.Password를 직접 쓰거나 파라미터의 Default에 저장하면 MongoDB 원본 엔드포인트의 인증 정보가 템플릿과 이력에 남습니다.

잠재적 영향

데이터베이스에 연결할 수 있는 사람이 비밀번호를 얻으면 마이그레이션 계정에 허용된 범위에서 원본 데이터에 접근할 수 있습니다.

해결 방법

비밀번호를 기본값 없이 안전하게 전달하거나, DMS의 Secrets Manager 연동을 사용하세요. 파라미터에는 NoEcho: true를 설정하고 값을 로그·출력에 남기지 마세요. 노출된 비밀번호는 MongoDB에서 교체한 뒤 DMS 연결 정보도 갱신하고 연결을 확인하세요.

예시

MongoDB 원본 엔드포인트의 서버와 사용자 이름을 입력합니다. 변경 전 기본값은 예시 비밀번호입니다. 변경 후에는 기존 MongoDB 계정의 비밀번호를 MasterMongoDBPassword로 안전하게 전달합니다. 엔드포인트 설정은 데이터베이스 계정의 비밀번호를 변경하지 않습니다.

변경 전

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  MongoDBServer:
    Type: String
  ParentMasterUsername:
    Type: String
  MasterMongoDBPassword:
    Type: String
    Default: "as@3djdkDjskjs73!!"
Resources:
  NewAmpApp1:
    Type: AWS::DMS::Endpoint
    Properties:
      EngineName: mongodb
      EndpointType: source
      SslMode: require
      MongoDbSettings:
        AuthType: password
        AuthSource: admin
        Password: !Ref MasterMongoDBPassword
        Port: 27017
        ServerName: !Ref MongoDBServer
        Username: !Ref ParentMasterUsername

변경 후

yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
  MongoDBServer:
    Type: String
  ParentMasterUsername:
    Type: String
  MasterMongoDBPassword:
    Type: String
    NoEcho: true
Resources:
  NewAmpApp1:
    Type: AWS::DMS::Endpoint
    Properties:
      EngineName: mongodb
      EndpointType: source
      SslMode: require
      MongoDbSettings:
        AuthType: password
        AuthSource: admin
        Password: !Ref MasterMongoDBPassword
        Port: 27017
        ServerName: !Ref MongoDBServer
        Username: !Ref ParentMasterUsername

참조