【问题标题】:How to get AWS secret value in JS?如何在 JS 中获取 AWS 秘密值?
【发布时间】:2021-10-12 00:36:39
【问题描述】:

我是使用 AWS 的新手,我可以手动获取所需的密钥,但我正在尝试使用 AWS 中提供的代码 sn-p 来获取密钥值,但我尝试的所有操作都返回未定义,请谁能告诉我我做错了什么?

// Load the AWS SDK
var AWS = require('aws-sdk'),
    region = "REMOVED",
    secretName = "REMOVED",
    secret,
    decodedBinarySecret;

// Create a Secrets Manager client
var client = new AWS.SecretsManager({
    region: region
});

// In this sample we only handle the specific exceptions for the 'GetSecretValue' API.
// See https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_GetSecretValue.html
// We rethrow the exception by default.

client.getSecretValue({SecretId: secretName}, function(err, data) {
    if (err) {
        if (err.code === 'DecryptionFailureException')
            // Secrets Manager can't decrypt the protected secret text using the provided KMS key.
            // Deal with the exception here, and/or rethrow at your discretion.
            throw err;
        else if (err.code === 'InternalServiceErrorException')
            // An error occurred on the server side.
            // Deal with the exception here, and/or rethrow at your discretion.
            throw err;
        else if (err.code === 'InvalidParameterException')
            // You provided an invalid value for a parameter.
            // Deal with the exception here, and/or rethrow at your discretion.
            throw err;
        else if (err.code === 'InvalidRequestException')
            // You provided a parameter value that is not valid for the current state of the resource.
            // Deal with the exception here, and/or rethrow at your discretion.
            throw err;
        else if (err.code === 'ResourceNotFoundException')
            // We can't find the resource that you asked for.
            // Deal with the exception here, and/or rethrow at your discretion.
            throw err;
    }
    else {
        // Decrypts secret using the associated KMS CMK.
        // Depending on whether the secret is a string or binary, one of these fields will be populated.
        if ('SecretString' in data) {
            secret = data.SecretString;
        } else {
            let buff = new Buffer(data.SecretBinary, 'base64');
            decodedBinarySecret = buff.toString('ascii');
        }
    }
    
    // Your code goes here. 
    var x = client.getSecretValue("REMOVED")

【问题讨论】:

  • 这段代码在哪里运行?在 EC2 上,Lambda ...?您为执行设置了什么角色?这可能是权限问题。
  • 当你说它返回undefined时,你的意思是回调中data的值是undefined吗?您是否 100% 确定 err 也未定义?
  • 我只是想在我的笔记本电脑上运行它
  • 您没有处理回调中的所有潜在错误。任何不属于所列错误之一的错误都将被静默抑制。在你的回调中打印出错误和数据。

标签: javascript node.js amazon-web-services aws-sdk


【解决方案1】:

请试试这个方法

import AWS from 'aws-sdk';

const client = new AWS.SecretsManager();

export default async () => {
  const secretName = `YOUR_SECRET_NAME`;
  try {
    console.log('Getting secrets');
    let secret;
    const data = await client.getSecretValue({ SecretId: secretName }).promise();
    if (data.SecretString) secret = data.SecretString;
    console.log('secret: ', secret);
    return secret ? JSON.parse(secret) : secret
  } catch (err) {
    if (err.code === 'ResourceNotFoundException') {
      console.log(`The requested secret ${secretName} was not found`);
    } else if (err.code === 'InvalidRequestException') {
      console.log(`The request was invalid due to: ${err.message}`);
    } else if (err.code === 'InvalidParameterException') {
      console.log(`The request had invalid params: ${err.message}`);
    }
    throw error;
  }
};

导入这个js文件并调用函数。

此外,如果您在本地计算机上运行此代码,请不要忘记配置您的 AWS CLI。对于配置,您可以使用以下方式之一

  1. 在终端中使用 aws configure 命令,并按照说明进行操作
  2. 在终端中运行此命令
    export AWS_ACCESS_KEY_ID=YOUR_ACCESS_KEY_HERE export AWS_SECRET_ACCESS_KEY=YOUR_SECRET_KEY_HERE export AWS_REGION=YOUR_REGION_HERE

【讨论】:

  • 为什么你认为用基于承诺的解决方案替换回调解决方案会有所作为?
  • 愚蠢的问题,但我如何调用该函数?当我尝试时,它说 getSecrets 未定义
  • 您是否将导入作为默认导出函数? import getSecrets from './getSecrets.js'如果你的文件名是getSecrets.js
  • 这段代码与OP的代码基本相同,但使用了promisified SDK,不会有任何区别。两组代码都可以正常工作,并且可以很好地检索文本机密。 OP 缺少一些东西。
  • 可能是有关 AWS 配置的问题。 @Doctor 你是谁设置了 AWS 访问和密钥?
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2020-10-01
  • 2021-05-02
  • 2017-10-02
  • 1970-01-01
  • 2021-04-16
  • 1970-01-01
相关资源
最近更新 更多