AWS datasync: Clarified secret management options with KMS and IAM roles
Summary
Added details about credential types (Kerberos/SAS) and explicit API references for secret configurations, emphasizing customer-managed keys and IAM roles.
Security assessment
The change explicitly documents encryption with customer-managed KMS keys and IAM role usage for secret access, improving security best practice guidance.
Evidence
+ * [CmkSecretConfig](https://docs.aws.amazon.com/datasync/latest/userguide/API_CmkSecretConfig.html): DataSync-Managed Secret with a Customer Managed Key configuration. Store the secret in Secrets Manager using a DataSync service-managed secret encrypted with an AWS KMS key that you manage.
Diff
diff --git a/datasync/latest/userguide/location-credentials.md b/datasync/latest/userguide/location-credentials.md index 956bdbeb5..201e7c84c 100644 --- a//datasync/latest/userguide/location-credentials.md +++ b//datasync/latest/userguide/location-credentials.md @@ -15 +15 @@ Secrets Manager integration is available for object storage and Microsoft Azure -DataSync uses [locations](https://docs.aws.amazon.com/datasync/latest/userguide/how-datasync-transfer-works.html#sync-locations) to access your storage resources located on premises, in other clouds, or in AWS. Some location types require you to provide credentials, such as an access key and secret key or a user name and password, to authenticate with your storage system. When you create a DataSync location that requires credentials for authentication, you can use AWS Secrets Manager (Secrets Manager) to store the secret for your credentials. The following options are available: +DataSync uses [locations](https://docs.aws.amazon.com/datasync/latest/userguide/how-datasync-transfer-works.html#sync-locations) to access your storage resources located on premises, in other clouds, or in AWS. Some location types require credentials to authenticate with your storage system. Credential types include an access key and secret key, a user name and password, a Kerberos keytab, or a SAS token. When you create a DataSync location that requires credentials for authentication, you can use AWS Secrets Manager (Secrets Manager) to store the secret for your credentials. The following options are available: @@ -17 +17 @@ DataSync uses [locations](https://docs.aws.amazon.com/datasync/latest/userguide/ - * Store the secret in Secrets Manager using a service-managed secret encrypted with a default key. + * [ManagedSecretConfig](https://docs.aws.amazon.com/datasync/latest/userguide/API_ManagedSecretConfig.html): DataSync-Managed Secret configuration. Store the secret in Secrets Manager using a DataSync service-managed secret encrypted with a default key. @@ -19 +19 @@ DataSync uses [locations](https://docs.aws.amazon.com/datasync/latest/userguide/ - * Store the secret in Secrets Manager using a service-managed secret encrypted with an AWS KMS key that you manage. + * [CmkSecretConfig](https://docs.aws.amazon.com/datasync/latest/userguide/API_CmkSecretConfig.html): DataSync-Managed Secret with a Customer Managed Key configuration. Store the secret in Secrets Manager using a DataSync service-managed secret encrypted with an AWS KMS key that you manage. @@ -21 +21 @@ DataSync uses [locations](https://docs.aws.amazon.com/datasync/latest/userguide/ - * Store the secret in Secrets Manager using a secret and key that you create and manage. DataSync accesses this secret using an IAM role that you provide. + * [CustomSecretConfig](https://docs.aws.amazon.com/datasync/latest/userguide/API_CustomSecretConfig.html): Customer-Managed Secret configuration. Store the secret in Secrets Manager using a secret and key that you create and manage. DataSync accesses this secret using an IAM role that you provide.