← AWS Developer Associate: applications and operations
04 / 7 · 30 MIN

Secrets, keys, and useful logs

Prepare rotation and diagnosis without exposing credentials.

Concept and mechanism

A secret should not require rebuilding the application whenever it changes. Runtime retrieval with limited permissions separates credentials from artifacts. A cache can reduce calls and latency but needs validity and refresh behavior consistent with rotation. If the database password changes while a consumer indefinitely retains the previous one, availability depends on manual restarts. Rotation involves both the secret-manager value and the credential accepted by the target. Test new connections and update failures without printing sensitive values. Record appropriate versions or states while limiting access to diagnostic data.

Guided application

Encrypting data also requires key authorization management. In KMS, inspect the key policy, IAM policies, and applicable grants; an isolated IAM Allow does not create missing delegation. Before widening permissions, confirm the actual key, Region, principal, and operation. Operational investigation should use correlation, result codes, and minimal context. Tokens, passwords, and credential-bearing URLs should not enter logs merely because the level is DEBUG. During an incident, observe whether errors started after rotation, a role change, or a key change. That sequence guides more useful hypotheses than increasing resources without saturation evidence.

IN PRACTICE

If the application caches for 24 hours but the password rotates sooner, define and rehearse compatible refresh, including authentication-error behavior and bounded retry.

Common pitfalls

Plaintext variables treated as a permanent solution; cache without expiry; ignored key policies; passwords logged for support convenience.

Related topics: Artifacts, tests, and environments · Gradual deployment and recovery

Take this idea with you

Availability and confidentiality depend on the credential’s full lifecycle.

Create account

Reference: Secret rotation · DVA-C02; exam guide 2.1