설명
CloudFormation의 AWS::DMS::Endpoint에서 MongoDbSettings.Password를 직접 쓰거나 파라미터의 Default에 저장하면 MongoDB 원본 엔드포인트의 인증 정보가 템플릿과 이력에 남습니다.
잠재적 영향
데이터베이스에 연결할 수 있는 사람이 비밀번호를 얻으면 마이그레이션 계정에 허용된 범위에서 원본 데이터에 접근할 수 있습니다.
해결 방법
비밀번호를 기본값 없이 안전하게 전달하거나, DMS의 Secrets Manager 연동을 사용하세요. 파라미터에는 NoEcho: true를 설정하고 값을 로그·출력에 남기지 마세요. 노출된 비밀번호는 MongoDB에서 교체한 뒤 DMS 연결 정보도 갱신하고 연결을 확인하세요.
예시
MongoDB 원본 엔드포인트의 서버와 사용자 이름을 입력합니다. 변경 전 기본값은 예시 비밀번호입니다. 변경 후에는 기존 MongoDB 계정의 비밀번호를 MasterMongoDBPassword로 안전하게 전달합니다. 엔드포인트 설정은 데이터베이스 계정의 비밀번호를 변경하지 않습니다.
변경 전
yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
MongoDBServer:
Type: String
ParentMasterUsername:
Type: String
MasterMongoDBPassword:
Type: String
Default: "as@3djdkDjskjs73!!"
Resources:
NewAmpApp1:
Type: AWS::DMS::Endpoint
Properties:
EngineName: mongodb
EndpointType: source
SslMode: require
MongoDbSettings:
AuthType: password
AuthSource: admin
Password: !Ref MasterMongoDBPassword
Port: 27017
ServerName: !Ref MongoDBServer
Username: !Ref ParentMasterUsername
변경 후
yaml
AWSTemplateFormatVersion: '2010-09-09'
Parameters:
MongoDBServer:
Type: String
ParentMasterUsername:
Type: String
MasterMongoDBPassword:
Type: String
NoEcho: true
Resources:
NewAmpApp1:
Type: AWS::DMS::Endpoint
Properties:
EngineName: mongodb
EndpointType: source
SslMode: require
MongoDbSettings:
AuthType: password
AuthSource: admin
Password: !Ref MasterMongoDBPassword
Port: 27017
ServerName: !Ref MongoDBServer
Username: !Ref ParentMasterUsername