< ciso
brief />
Tag Banner

All news with #aws secrets manager tag

34 articles

Improving SPIRE Security and Resiliency on AWS

๐Ÿ”’ This post explains how to strengthen SPIRE (the SPIFFE Runtime Environment) deployments by offloading core functions to AWS managed services. It outlines replacing default SPIRE components with AWS KMS, AWS Private CA, Amazon Aurora, Amazon S3, AWS Secrets Manager, and Amazon Verified Permissions to improve security, scalability, and operational resiliency. A GitHub repository provides deployment templates and configuration examples to follow along.
read more โ†’

AWS releases advanced Ruby driver wrapper for RDS/Aurora

๐Ÿš€ The AWS Advanced Ruby Driver Wrapper is now generally available for Amazon RDS and Amazon Aurora PostgreSQL and MySQL-compatible databases. It reduces RDS Blue/Green switchover, Aurora Global database switchover and failover times to improve application availability and supports authentication via AWS Secrets Manager and token-based AWS IAM. Built on the community pg and mysql2 drivers, it integrates with Aurora/RDS to detect cluster status and reconnect to promoted writers, and provides aws_postgresql and aws_mysql2 ActiveRecord adapters so applications require no code changes.
read more โ†’

AgentCore Gateway adds private TLS for VPC endpoints

๐Ÿ”’ Amazon Bedrock AgentCore Gateway now accepts TLS certificates signed by private certificate authorities for MCP, OpenAPI, and HTTP proxy targets, enabling secure native connections to private endpoints in your VPC without an intermediate Application Load Balancer. You can register PEM-encoded CA certificates stored in Amazon S3 or AWS Secrets Manager, which the gateway uses as a trust anchor for outbound TLS. This support is available in all Regions where AgentCore Gateway and Amazon VPC Lattice are offered. See the AgentCore Developer Guide for details.
read more โ†’

AWS Secrets Manager adds security posture recommendations

๐Ÿ”’ AWS Secrets Manager now integrates with the AWS Recommended Actions framework to display contextual, actionable suggestions directly in the Secrets Manager console. Users can view tailored recommendations beside individual secrets to improve security posture and follow best practices without leaving the console. Examples include enabling rotation, switching to customer-managed keys for encryption, and addressing configuration improvements. This capability is available in all AWS Regions where Secrets Manager is offered, at no additional cost.
read more โ†’

AWS August 2026 Security Update Digest

๐Ÿ”’ Augustโ€™s AWS Security digest highlights new service capabilities, compliance updates, and hands-on resources across identity, data protection, AI security, detection, and governance. It summarizes 20+ blog posts, security bulletins, and 17 code samples focused on agent governance, credential protection, and automated compliance. The update emphasizes prompt patching and practical deployment guidance for enterprise security teams.
read more โ†’

Transfer Family SFTP connectors support credential rotation

๐Ÿ”’ AWS Transfer Family SFTP Connectors now continue file transfers while you rotate authentication credentials, eliminating the need to repoint connectors to new secret versions. Connectors can retrieve credentials from an ordered list of AWS Secrets Manager version stages (for example, current and previous) and will try each version in sequence until authentication succeeds. This behavior is configured when creating or updating a connector, requires storing credentials in AWS Secrets Manager, and is available in all Regions where Transfer Family SFTP Connectors are supported.
read more โ†’

AWS adds oneโ€‘click install for Workload Credentials

๐Ÿ› ๏ธ AWS Secrets Manager now offers oneโ€‘click installation for the AWS Workload Credentials Provider (AWCP) on Amazon Linux and Windows, replacing a prior multiโ€‘step build-from-source flow. Pre-built, code-signed binaries for Linux (x86_64, ARM64) and Windows (x64) are available via public download and the Amazon Linux repository, enabling one-command install on Amazon Linux EC2. AWCP resolves secrets from AWS Secrets Manager, caches them in memory, and exposes them via a local HTTP endpoint; it also retrieves certificates from AWS Certificate Manager. The feature is available in all Regions where Secrets Manager is offered at no extra charge beyond standard Secrets Manager pricing.
read more โ†’

Secrets Manager Adds Cisco and Netskope Rotations

๐Ÿ”’ AWS Secrets Manager now supports managed external secrets for Cisco Security Platform API keys and Netskope API tokens, allowing automated rotation directly from the AWS console without custom rotation code. Cisco rotations refresh the API key's refresh token on a schedule so applications continue to obtain short-lived access tokens. Netskope rotations update RBACv3 service-account tokens via SCIM and validate the new token before completion. These self-authenticating integrations require no separate administrator credential and are available in all Regions where managed external secrets are supported.
read more โ†’

Use Request Lambda Interceptor for Basic Auth Bridge

๐Ÿ”’ This post explains how to implement a request Lambda interceptor in Amazon Bedrock AgentCore Gateway to support legacy HTTP Basic Authentication for downstream tool APIs. It shows retrieving a service account credential from AWS Secrets Manager, validating inbound JWTs, and constructing a Basic Auth header while keeping credentials isolated from the agent. The article emphasizes that Basic Auth is outdated and recommends modern authentication like OAuth 2.0 or OpenID Connect, presenting this pattern only as an interim integration.
read more โ†’

AWS Secrets Manager Adds Jenkins and SonarQube Token Rotation

๐Ÿ” AWS Secrets Manager now supports managed external secrets for Jenkins API Tokens and SonarQube Tokens, enabling automatic rotation and lifecycle management directly from the AWS console. For Jenkins, Secrets Manager mints new tokens and revokes old ones only after verifying the replacement is active, supporting both self-rotation and admin-assisted rotation. SonarQube rotation covers User Tokens, Global Analysis Tokens, and Project Analysis Tokens via the SonarQube Web API, with user tokens supporting self-rotation and analysis tokens rotated using an admin token. These additions join other supported services and are available in all Regions where managed external secrets is supported.
read more โ†’

Secrets Manager publishes secret update events

๐Ÿ”” AWS Secrets Manager now publishes events to Amazon EventBridge when secret values change, enabling event-driven responses without parsing CloudTrail. You can create EventBridge rules to detect active secret value changes and route them to targets like AWS Lambda, Amazon SNS, Amazon SQS, or Amazon Step Functions. Notifications are published to the default event bus automatically, require no opt-in, and are available in all Regions where AWS Secrets Manager is offered at no extra cost.
read more โ†’

AWS Secrets Manager adds Paddle and GitLab support

๐Ÿ” AWS Secrets Manager now supports managed external secrets for Paddle API Keys and GitLab Access Tokens. This feature enables automatic rotation of third-party credentials directly from AWS Secrets Manager, using Paddle's native rotation API and GitLab's atomic rotation mechanism. Customers can rotate Paddle API keys with a configurable grace period and rotate GitLab Personal, Group, and Project Access Tokens. These integrations join existing partners and are available in all Regions where managed external secrets is supported.
read more โ†’

Agent Toolkit Adds Secret Safety Skill for Agents

๐Ÿ”’ AWS Secrets Manager introduces a secret safety skill in the aws-core plugin for the Agent Toolkit for AWS, enabling AI coding agents to use secrets without exposing values to models or session logs. The skill prevents models from requesting raw secret values and prompts developers to clarify intent while constructing commands that reference secrets. A child process resolves secret references at execution time, keeping plaintext secrets out of agent context and logs. The feature is available across supported agent harnesses and Regions where Secrets Manager is offered.
read more โ†’

AWS Secrets Manager adds Datadog and Snowflake support

๐Ÿ” AWS Secrets Manager now supports managed external secrets for Datadog vended keys and Snowflake Programmatic Access Tokens, enabling automatic rotation of third-party credentials directly within Secrets Manager. The update covers Datadog API keys, Application keys, and admin credential pairs for service accounts. For Snowflake, Secrets Manager can rotate Programmatic Access Tokens using Snowflake's native authentication and offers a configurable grace period to minimize disruption. These additions join existing integrations such as BigID, Confluent Cloud, MongoDB Atlas, and Salesforce and are available in all Regions where managed external secrets is supported.
read more โ†’

Secrets Manager Agent Adds Pre-Fetching and Role Assumption

๐Ÿ”’ The AWS Secrets Manager Agent now supports pre-fetching secrets at startup and assuming an IAM role for retrieval. With pre-fetching you can specify a list of secrets or a tag to retrieve and cache via BatchGetSecretValue, reducing application startup latency and API overhead. The agent can also assume a provided role ARN per pre-fetch or HTTP request to enable cross-account secret retrieval. These capabilities are available in all Regions where Secrets Manager is offered.
read more โ†’

AWS Secrets Manager Enables Hybrid Post-Quantum TLS

๐Ÿ” AWS Secrets Manager now prefers hybrid post-quantum TLS (MLโ€‘KEM) for supported clients to reduce harvest-now, decrypt-later risk. Customers using the listed clients and SDK versions can get MLโ€‘KEM key exchange without code changes; secrets at rest remain encrypted with AWS KMS and symmetric algorithms are considered quantum-resistant. Verify client negotiation via CloudTrail tlsDetails.keyExchange == X25519MLKEM768 and check SDK/OpenSSL requirements (for example, OpenSSL 3.5+ for Python). CRYSTALSโ€‘Kyber support is being phased out in 2026, so upgrades are recommended to avoid fallback to traditional TLS.
read more โ†’

AWS Secrets Manager Adds MongoDB and Confluent Support

๐Ÿ” AWS Secrets Manager now supports managed external secrets for MongoDB Atlas and Confluent Cloud, enabling centralized secret storage and automatic rotation without building custom Lambda rotation functions. The MongoDB integration handles database user credentials (SCRAM) and service account OAuth client ID/secret; Confluent automates API key rotation for service accounts with cluster-scoped and cloud resource management keys. Automatic rotation is enabled by default to remove hardcoded credentials and reduce operational overhead.
read more โ†’

AWS Secrets Manager Adds Hybrid Postโ€‘Quantum TLS Support

๐Ÿ” AWS Secrets Manager now supports hybrid post-quantum TLS key exchange using ML-KEM (a module-lattice-based KEM) to secure secret retrieval. The capability is automatically enabled in Secrets Manager Agent (v2.0.0+), Lambda Extension (v19+), and Secrets Manager CSI Driver (v2.0.0+); supported SDKs include Rust, Go, Node.js, Kotlin, Python (OpenSSL 3.5+), and Java v2 (v2.35.11+). No code or configuration changes are required for up-to-date clients except Java v2. You can verify hybrid key exchange in CloudTrail GetSecretValue events by checking the tlsDetails field for the X25519MLKEM768 algorithm.
read more โ†’

AWS Secrets Manager Console Accepts Custom KMS ARNs

๐Ÿ”’ The AWS Secrets Manager console now lets you enter a custom customer-managed AWS KMS key ARN when creating secrets. Previously, the console only presented keys from the current account in a dropdown. By accepting direct KMS key ARNs, the console now supports keys in other accounts and aligns with existing API capabilities. This change simplifies cross-account encryption workflows and offers more flexible key management across accounts.
read more โ†’

AWS DataSync Adds Secrets Manager Support for All Locations

๐Ÿ” AWS DataSync now integrates with AWS Secrets Manager for credential management across all DataSync location types, including HDFS and Amazon FSx variants. Customers can centralize secrets in their account and optionally encrypt them with a customer-managed AWS KMS key to meet governance requirements. DataSync supports providing a secret ARN you manage or having DataSync automatically create and manage secrets. This capability is available in the majority of AWS regions where DataSync is offered.
read more โ†’