mirror of
https://github.com/Sea-Haven-Industries/engineering-handbook.git
synced 2026-09-30 08:03:16 +00:00
Partner engineering teams need the standards without access to this repo, which contains internal repo names, account identifiers, and migration history. Adds eight simplified pages, one per Confluence page, plus an internal README with source mapping and exclusions. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01UP6j3hYgoVqjKZwC3XB9ay
1.9 KiB
1.9 KiB
Secrets and Configuration
Sensitive and non-sensitive configuration are kept strictly apart.
AWS Secrets Manager: sensitive values
Use Secrets Manager for every sensitive value:
- API tokens and keys
- Signing secrets used to verify requests
- Webhook URLs that act as authentication
- Connection strings containing passwords
- Anything that would cause harm if leaked
If you are unsure whether something is sensitive, treat it as sensitive.
Name secrets <stack-name>/<value-name>, for example my-stack/stripe-key.
SSM Parameter Store: non-sensitive values
Use Parameter Store only for non-sensitive configuration:
- Feature flags
- Public endpoint URLs
- Schedule expressions
- Non-sensitive identifiers, such as channel IDs
- Resource names that deploy pipelines read, such as bucket names and function names
Reading secrets in a Lambda
- Store the value in Secrets Manager.
- Grant the function's role
secretsmanager:GetSecretValueon only the secrets it needs. - Read the secret on cold start and cache it in a module-level variable.
import json
import boto3
_client = boto3.client("secretsmanager")
_cached = None
def get_config():
global _cached
if _cached is None:
resp = _client.get_secret_value(SecretId="my-stack/config")
_cached = json.loads(resp["SecretString"])
return _cached
def handler(event, context):
config = get_config()
# use config values
Never
- Put sensitive values in Lambda environment variables. They show in plain text in the AWS console.
- Commit
.envfiles or any file containing real credentials. - Share credentials in Jira, Confluence, Slack, email, or any other plain-text tool.
- Hardcode account IDs, ARNs, or resource names that belong in configuration.
If a secret is committed or exposed by mistake, tell your Sea Haven contact immediately so it can be rotated. Deleting the commit is not enough.