9.0 KiB
title, source_type, url, archive_url, status, confidence, tags, related_projects, related_branches, created, last_reviewed
| title | source_type | url | archive_url | status | confidence | tags | related_projects | related_branches | created | last_reviewed | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AWS Secrets Manager — Automatic rotation (Lambda / managed) | official-doc | https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotating-secrets.html | raw | high |
|
|
|
2026-05-22 | 2026-05-27 |
AWS Secrets Manager — Secret Rotation
Layer:
raw/official-docs/— AWS Secrets Manager User Guide / "Rotating secrets" 섹션 원문 발췌. ca-tmplfeature-secrets-config-source-contract의 baseline rotation 모델 (managed / Lambda) 의 1차 근거.
Parent / 활용 branch (필수)
| Branch | 이 자료가 정당화하는 결정 |
|---|---|
| raw/branch-notes/feature-secrets-config-source-contract | prod source = AWS Secrets Manager OR GCP Secret Manager OR Vault + DB credential rotation dual-bind 60s 정책의 1차 근거 — managed / Lambda rotation 의 공식 권장 패턴 검증 |
| raw/branch-notes/feature-security-operational-baseline | JWT signing key rotation 24h overlap 의 cross-link — AWSPREVIOUS staging label 의 rollback 가능성 모델 |
| raw/project-notes/ca-skeleton-operational-contract | Secrets Config Source Contract — baseline 채택 후보 (대안 1) |
컨텍스트 / 왜 저장했는지
feature-secrets-config-source-contract ca-tmpl이 결정한 prod source = AWS Secrets Manager OR GCP Secret Manager OR Vault + DB credential rotation dual-bind 60s 정책의 1차 근거. baseline의 rotation 모델이 공식 권장 패턴(managed / Lambda)을 따르는지 검증.
출처 / Source
- 원본 URL: https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotating-secrets.html
- 아카이브 URL: (미확보)
- 저자 / 조직: Amazon Web Services — Secrets Manager User Guide
- 발행 상태: rolling docs (페이지 자체에 명시 없음)
- 관련: staging label
AWSCURRENT/AWSPENDING/AWSPREVIOUS, RDS rotation, multi-user rotation strategy - 마지막 확인일: 2026-05-27
핵심 인용 / Key quotes (verbatim)
[§Rotating secrets — Overview, 2026-05-27 verified] "Rotation is the process of periodically updating a secret. When you rotate a secret, you update the credentials in both the secret and the database or service."
[§Rotation models — Managed rotation, 2026-05-27 verified] "Managed rotation – For most managed secrets, you use managed rotation, where the service configures and manages rotation for you. Managed rotation doesn't use a Lambda function."
[§Rotation models — Managed external, 2026-05-27 verified] "Rotate Secrets Manager managed external secrets – For secrets held by Secrets Manager partners, you use managed external secrets rotation to update the secret on the partner's system. This doesn't require a Lambda function."
[§Rotation models — Lambda, 2026-05-27 verified] "Rotation by Lambda function – For other types of secrets, Secrets Manager rotation uses a Lambda function to update the secret and the database or service."
재검증 완료 (2026-05-27): WebFetch 권한 복구 후 https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotating-secrets.html 원본에서 위 4개 인용 모두 verbatim 일치 확인. 단 dash 문자가 en-dash "–" 인 점 + Managed external 항목에 "This doesn't require a Lambda function." 한 문장이 추가로 존재함을 확인. Strength
needs-confirmation→official-vendor-doc로 격상 (AWS 공식 User Guide).
Claims Extracted / 추출된 주장
| Claim ID | Claim (이 자료가 직접 말하는 것) | Evidence quote | Strength | Applies to | Does not prove |
|---|---|---|---|---|---|
| AWS-SM-ROTATE-C1 | rotation 은 secret 의 주기적 갱신 과정이며, secret 과 DB/service 양쪽의 credential 을 함께 업데이트 | [§Overview] "Rotation is the process of periodically updating a secret. When you rotate a secret, you update the credentials in both the secret and the database or service." | official-vendor-doc |
AWS Secrets Manager 의 모든 rotation 시나리오 | rotation 주기 (24h / 30d 등) 의 권장값이 명시되어 있다는 뜻은 아님 — 정책별 결정 |
| AWS-SM-ROTATE-C2 | 대부분의 managed secret 은 managed rotation 사용 (서비스가 직접 rotation 관리, Lambda 불필요) | [§Managed rotation] "Managed rotation – For most managed secrets, you use managed rotation, where the service configures and manages rotation for you. Managed rotation doesn't use a Lambda function." | official-vendor-doc |
RDS / DocumentDB 등 managed AWS service 의 secret | 모든 secret 타입에서 managed rotation 이 가능하다는 뜻은 아님 — Lambda 모델이 필요한 경우 별도 |
| AWS-SM-ROTATE-C3 | Secrets Manager partner 가 보유한 secret 은 managed external rotation 으로 partner system 측 업데이트 (Lambda 불필요) | [§Managed external] "Rotate Secrets Manager managed external secrets – For secrets held by Secrets Manager partners, you use managed external secrets rotation to update the secret on the partner's system. This doesn't require a Lambda function." | official-vendor-doc |
Secrets Manager partner 통합 시 | partner 목록 / 지원 범위 / SLA 는 본 인용 범위 밖 |
| AWS-SM-ROTATE-C4 | 위 두 모델에 해당하지 않는 secret 은 Lambda function 기반 rotation 으로 사용자 코드가 secret 과 DB/service 양쪽 업데이트 | [§Lambda] "Rotation by Lambda function – For other types of secrets, Secrets Manager rotation uses a Lambda function to update the secret and the database or service." | official-vendor-doc |
managed 모델 외 모든 secret | Lambda 코드의 template / 예제가 자동 제공된다는 뜻은 아님 — multi-user / single-user strategy 별도 선택 |
Usage Boundaries / 적용 경계
- 이 자료가 직접 증명하는 것:
AWS-SM-ROTATE-C1~C4: AWS Secrets Manager 의 rotation 3가지 모델 (managed / managed external / Lambda) 의 공식 정의
- 이 자료가 증명하지 않는 것:
- staging label
AWSCURRENT/AWSPENDING/AWSPREVIOUS의 전이 메커니즘 (별도 staging label 페이지) - multi-user rotation strategy 의 정확한 메커니즘 (dual-bind window 의 default 값 등)
- rotation 비용 (per-secret pricing + API call pricing)
- CloudTrail audit 의 자동 활성화 여부
- 다른 cloud (GCP Secret Manager / Vault) 와의 rotation 모델 동등성
- staging label
- 내 프로젝트에 적용하려면 추가 확인이 필요한 것:
- ca-tmpl 의 dual-bind 60s 정책이 Lambda multi-user rotation 의 default window 와 일치하는지 (별도 multi-user strategy 페이지 검증)
restart-onlyreload 정책 하에서 AWSCURRENT 변경이 어떻게 application 까지 전파되는지 (cache 만료 / 명시 restart 전략)__LOCAL_DEV_sentinel prefix 가 local fake credential 의 prod 누출 방지에 충분한지 (startup guard 별도 구현 필요)
메모 / Notes (내 프로젝트 해석)
본 섹션은 자료 직접 인용 아님. ca-tmpl 적용 컨텍스트 해석.
- 3가지 rotation 모델:
- Managed rotation (RDS, DocumentDB 등) — AWS가 직접 갱신.
- Managed external (파트너) — 파트너가 갱신.
- Lambda rotation — 사용자 정의 함수.
- dual-bind 패턴 (ca-tmpl baseline 60s):
- Lambda rotation의 multi-user strategy: 두 user(
user1,user2)를 번갈아 회전 → application은AWSCURRENT라벨만 읽음. - rotation 중 잠시 두 credential 모두 유효한 window가 필요 → ca-tmpl의 dual-bind 60s가 이를 위한 기준.
- Lambda rotation의 multi-user strategy: 두 user(
- ca-tmpl 결정과의 매핑:
- prod = secret manager OR mounted env → AWS Secrets Manager가 valid path.
restart-onlyreload → AWSCURRENT가 바뀌면 application restart로 fetch. cache 만료 또는 명시 restart.- dual-bind 60s → multi-user rotation window의 운영 default.
- 장점:
- managed rotation은 Lambda 코드 작성 불필요 (RDS/Redshift 등).
- staging label로 rollback 가능 (
AWSPREVIOUS). - CloudTrail audit 자동.
- 단점:
- cloud lock-in.
- Lambda rotation은 사용자 코드 부담 (DB 호환성, network 접근, retry).
- 비용 (secret 당 요금 + API call 요금).
- vs ca-tmpl
__LOCAL_DEV_sentinel:- Secrets Manager는 prod 전용 가정. local은
.env. sentinel prefix는 local fake가 prod에 새지 않도록 startup 차단.
- Secrets Manager는 prod 전용 가정. local은
Related / 관련
- 같은 주제 다른 raw:
- 인용하는 branch:
- 인용하는 project:
- 대안 그룹: Group G-B — Secrets sub-topic
- 본 source의 위치: 대안 1 — AWS Secrets Manager + auto-rotation (baseline 채택 후보)
- 인용한 wiki 요약: (미작성)