Skip to main content

Simple secrets management powered by Amazon S3 + KMS

Project description

https://img.shields.io/pypi/v/microsecrets.svg

Microsecrets is a secrets distribution tool powered by Amazon S3 and Amazon KMS. It provides a bare-bones approach to passing credentials securely in an Amazon Web Services environment. Credentials are uploaded to S3 and encrypted at rest by KMS. They can then be passed to programs through environment variables.

Installation

$ pip install microsecrets

Usage

  1. Create the S3 bucket you’ll use for secrets storage. You may want one bucket per organization, such as example.com-microsecrets.

  2. Create one KMS master key for each service that will be using microsecrets. The key should by default be named microsecrets-myservice for a service called myservice. Users uploading the credentials and systems downloading the credentials will need privileges to encrypt/decrypt data using this key. None of the normal users need key administration privileges.

  3. Upload an environment file. Environment variables may be passed as = separated pairs on stdin or in a file. NB: whitespace is stripped and all other characters are treated literally. Or pass them as a JSON dict with the --json flag.

    $ microsecrets-upload -b example-microsecrets -s myservice <<EOM
    DB_URL=db://user:pass@example.com:123
    PASSWORD=hunter2
    EOM
  4. Run a program with the credentials in the environment. To verify the integrity of data in S3, you must specify the checksum of the environment file (output by the upload tool) or whitelist specific environment variables. Or, if integrity is not a concern, whitelist all environment variables. The whitelist is designed to avoid accidentally allowing code execution through LD_PRELOAD or similar, which may or may not be a concern in your system layout.

    $ microsecrets-with-env -b example-microsecrets -s myservice -w 'DB_URL PASSWORD' -- /bin/myserver

See also

There is a variety of other recent work in this space that may be of interest:

License

MIT License

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

microsecrets-0.1.1.tar.gz (8.4 kB view hashes)

Uploaded source

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page