Amazon Web Services

Encryption & Secrets — KMS, Secrets Manager & Parameter Store

Encrypt data at rest with managed keys and keep credentials out of code, environment variables and git.

KMS holds the keys. Secrets Manager and Parameter Store hold the values.

A bank vault that will not hand out the master key, but will lock and unlock the small key to your own box on request — and a service that quietly changes the lock every month.

Key Concepts

1
Envelope encryption is the mechanism to be able to explain.
    KMS generates a data key
      -> plaintext data key encrypts your data, then is discarded
      -> encrypted data key is stored beside the ciphertext
2
    to read: send the encrypted data key to KMS, get the plaintext
             back, decrypt locally
3
Your data never goes to KMS — only the small data key does. That is what makes it fast enough for terabytes and why the master key never leaves the service.
4
Key types.
    AWS managed      free, rotated yearly, no policy control
    customer managed  you control the policy, rotation and deletion.
                      Required for cross-account access and audit.
5
Key policies, not just IAM. A KMS key has its own resource policy, and access needs both it and IAM to allow. Locking yourself out of a key is permanent — deletion has a mandatory 7 to 30 day waiting period for exactly that reason.
6
Secrets Manager versus Parameter Store.
    Secrets Manager   automatic rotation (RDS integration built in),
                      cross-region replication, priced per secret
    Parameter Store   free standard tier, hierarchical paths,
                      SecureString via KMS, no rotation
7
Use Parameter Store for configuration, Secrets Manager for credentials you want rotated.
8
Rotation is the feature worth paying for. It changes the database password and updates the secret on a schedule, so a leaked credential has a short life.
9
Never pass a secret as a plain environment variable. It appears in the task definition, in the console and in logs. Fetch it at startup by name, or let the service inject it from the secret reference.
10
Encrypt in transit as well as at rest. aws:SecureTransport in a bucket policy denies plain HTTP, which is the condition auditors look for.
aws:SecureTransport
11
What the interviewer is probing.1. "Explain envelope encryption." Probing: whether you know why the data does not move. Stalls: "KMS encrypts the data." Moves up: KMS wraps a data key, the data key encrypts your data locally, and only the wrapped key is stored — a 5GB object never touches KMS.
12
2. "Secrets Manager or Parameter Store?" Probing: cost against capability. Stalls: "They are the same." Moves up: Secrets Manager for credentials you want rotated automatically; Parameter Store for configuration, with a free standard tier.
13
3. "Why not pass a secret as an environment variable?" Probing: where it leaks to. Stalls: "It is fine, it is not in code." Moves up: it appears in the task definition, the console and logs; fetch it at startup or inject it from a secret reference.
14
4. "Why does KMS key deletion take days?" Probing: the safety. Stalls: "Bureaucracy." *Moves up:* it is irreversible and makes every object encrypted with it unreadable, so there is a mandatory 7 to 30 day window to cancel.