Amazon Web Services
Encryption & Secrets — KMS, Secrets Manager & Parameter Store
Encrypt data at rest with managed keys and keep credentials out of code, environment variables and git.
KMS holds the keys. Secrets Manager and Parameter Store hold the values.
A bank vault that will not hand out the master key, but will lock and unlock the small key to your own box on request — and a service that quietly changes the lock every month.
Key Concepts
1
Envelope encryption is the mechanism to be able to explain.
KMS generates a data key
-> plaintext data key encrypts your data, then is discarded
-> encrypted data key is stored beside the ciphertext2
to read: send the encrypted data key to KMS, get the plaintext
back, decrypt locally3
Your data never goes to KMS — only the small data key does. That is what makes it fast enough for terabytes
and why the master key never leaves the service.
4
Key types.
AWS managed free, rotated yearly, no policy control
customer managed you control the policy, rotation and deletion.
Required for cross-account access and audit.5
Key policies, not just IAM. A KMS key has its own resource policy, and access needs both it and IAM to
allow. Locking yourself out of a key is permanent — deletion has a mandatory 7 to 30 day waiting period for
exactly that reason.
6
Secrets Manager versus Parameter Store.
Secrets Manager automatic rotation (RDS integration built in),
cross-region replication, priced per secret
Parameter Store free standard tier, hierarchical paths,
SecureString via KMS, no rotation7
Use Parameter Store for configuration, Secrets Manager for credentials you want rotated.
8
Rotation is the feature worth paying for. It changes the database password and updates the secret on a
schedule, so a leaked credential has a short life.
9
Never pass a secret as a plain environment variable. It appears in the task definition, in the console
and in logs. Fetch it at startup by name, or let the service inject it from the secret reference.
10
Encrypt in transit as well as at rest. aws:SecureTransport in a bucket policy denies plain HTTP, which
is the condition auditors look for.
aws:SecureTransport
11
What the interviewer is probing.1. "Explain envelope encryption." Probing: whether you know why the data does not move.
Stalls: "KMS encrypts the data." Moves up: KMS wraps a data key, the data key encrypts your data
locally, and only the wrapped key is stored — a 5GB object never touches KMS.
12
2. "Secrets Manager or Parameter Store?" Probing: cost against capability. Stalls: "They are
the same." Moves up: Secrets Manager for credentials you want rotated automatically; Parameter
Store for configuration, with a free standard tier.
13
3. "Why not pass a secret as an environment variable?" Probing: where it leaks to. Stalls:
"It is fine, it is not in code." Moves up: it appears in the task definition, the console and
logs; fetch it at startup or inject it from a secret reference.
14
4. "Why does KMS key deletion take days?" Probing: the safety. Stalls: "Bureaucracy." *Moves
up:* it is irreversible and makes every object encrypted with it unreadable, so there is a mandatory
7 to 30 day window to cancel.