AWS mgn: Windows Agent install: use STS env vars; avoid CLI credential exposure
Summary
Adds a non-interactive install procedure using AWS_ACCESS_KEY_ID/AWS_SECRET_ACCESS_KEY/AWS_SESSION_TOKEN environment variables with --no-prompt, recommends temporary AWS STS credentials, and adds a Warning that credentials passed as command-line parameters are visible to other users via the process list (e.g. Get-CimInstance Win32_Process), advising temporary credentials and rotation. Also includes minor typo fixes and a note that entered keys are hidden.
Security assessment
The added warning explicitly documents a credential-exposure weakness (secrets visible in the OS process list on a shared source server) and prescribes mitigations: prefer environment variables, use temporary STS credentials, and rotate after install. This is security best-practice documentation about credential handling rather than a fix for a specific vulnerability or incident.
Evidence
+Credentials that you pass as command-line parameters are visible to other users on the source server. They can view these credentials through the process list (for example, through the `Get-CimInstance Win32_Process` PowerShell command). To avoid exposing your credentials, use the environment variable method described in the previous step. If you do pass credentials as command-line parameters, use temporary credentials from AWS STS and rotate them after you install the Agent.
Diff
diff --git a/mgn/latest/ug/windows-agent.md b/mgn/latest/ug/windows-agent.md index b34269fe6..fb64eca77 100644 --- a//mgn/latest/ug/windows-agent.md +++ b//mgn/latest/ug/windows-agent.md @@ -33 +33 @@ https://aws-application-migration-service-hashes-us-east-1.s3.us-east-1.amazonaw - * We recommend using Windows PowerShell, which support ctrl+v pasting, and not Windows Command Prompt (cmd), which does not. + * We recommend using Windows PowerShell, which supports ctrl+v pasting, and not Windows Command Prompt (cmd), which does not. @@ -375,0 +376,7 @@ The installer confirms that the installation of the AWS Replication Agent has st +If you want to install the Agent without answering the interactive prompts, you can pass your credentials to the installer through environment variables instead. We recommend that you use temporary credentials from AWS Security Token Service (AWS STS). Open an elevated (Administrator) PowerShell session, set the `AWS_ACCESS_KEY_ID`, `AWS_SECRET_ACCESS_KEY`, and `AWS_SESSION_TOKEN` environment variables, and then run the installer with the `--no-prompt` option. The following PowerShell example sets these variables and runs the installer: + + PS C:\> $env:AWS_ACCESS_KEY_ID="AKIAIOSFODNN7EXAMPLE" + PS C:\> $env:AWS_SECRET_ACCESS_KEY="wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY" + PS C:\> $env:AWS_SESSION_TOKEN="AQoDYXdzEJr//////////wEa8AMDSomethingEXAMPLE" + PS C:\> .\AwsReplicationWindowsInstaller.exe --region us-east-1 --no-prompt + @@ -378 +385,11 @@ The installer confirms that the installation of the AWS Replication Agent has st -You can also enter these values as part of the installation script command parameters. If you do not enter these parameters as part of the installation script, you are prompted to enter them one by one as described above. (for example: ` AwsReplicationWindowsInstaller.exe --region regionname --aws-access-key-id AKIAIOSFODNN7EXAMPLE --aws-secret-access-key wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY)` + * You can also pass the AWS Access Key ID and AWS Secret Access Key as command-line parameters. In the following example, replace `regionname` with the AWS Region into which you are replicating: + + C:\> AwsReplicationWindowsInstaller.exe --region regionname --aws-access-key-id AKIAIOSFODNN7EXAMPLE --aws-secret-access-key wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY + +###### Warning + +Credentials that you pass as command-line parameters are visible to other users on the source server. They can view these credentials through the process list (for example, through the `Get-CimInstance Win32_Process` PowerShell command). To avoid exposing your credentials, use the environment variable method described in the previous step. If you do pass credentials as command-line parameters, use temporary credentials from AWS STS and rotate them after you install the Agent. + + * If you do not enter these parameters as part of the installation script, you are prompted to enter them one by one as described in the previous step. + + * The AWS Access Key ID and AWS Secret Access Key values are hidden when entered into the installer. @@ -384 +401 @@ You can also enter these values as part of the installation script command param -To replicate some of the disks, type the path of the disks, separated by a comma, as illustrated in the installer (for example: C: or D:). To replicate all of the disks, press **Enter**. The installer identifies the selected disks and print their size. +To replicate some of the disks, type the path of the disks, separated by a comma, as illustrated in the installer (for example: C: or D:). To replicate all of the disks, press **Enter**. The installer identifies the selected disks and prints their size. @@ -406 +423 @@ If disks are disconnected from a server, AWS Transform MGN can no longer replica -Note that the returned disks need be replicated from the beginning. Any disk size changes are automatically identified, but also cause a resync. Perform a test after installing the Agent to ensure that the correct disks have been added. +Note that the returned disks need to be replicated from the beginning. Any disk size changes are automatically identified, but also cause a resync. Perform a test after installing the Agent to ensure that the correct disks have been added.