如何用Terraform实现基于AWS托管Lambda的Aurora-PostgreSQL密钥轮换?
能复现,Terraform 1.9 + AWS Provider 5.62完全支持该配置
AWS控制台的预构建密钥轮换模板本质是部署了AWS维护的SAM应用(对应PostgreSQL的是SecretsManagerRDSPostgreSQLRotationSingleUser),同时创建配套IAM角色和Lambda函数。用Terraform可以完全复现这一流程,核心是通过aws_secretsmanager_secret_rotation资源配置轮换逻辑,结合Serverless Application Repository部署官方轮换Lambda。
核心实现步骤
1. 部署官方轮换SAM应用
直接引用AWS Serverless Application Repository中的预构建轮换应用,这和控制台模板的逻辑完全一致:
resource "aws_serverlessapplicationrepository_cloudformation_stack" "pg_rotation_stack" { name = "aurora-pg-secret-rotation" application_id = "arn:aws:serverlessrepo:us-east-1:297356227824:applications/SecretsManagerRDSPostgreSQLRotationSingleUser" semantic_version = "1.1.2" # 可替换为最新版本 parameters = { SecretId = aws_secretsmanager_secret.db_creds.id VpcSecurityGroupIds = aws_security_group.db_sg.id VpcSubnetIds = join(",", aws_subnet.private.*.id) MasterSecretArn = aws_secretsmanager_secret.db_creds.id # 单用户轮换模式下填自身 RotationIntervalInDays = "30" } }
该栈会自动生成轮换Lambda函数、IAM角色及必要权限,和控制台操作的输出完全一致。
2. 配置Secrets Manager密钥及轮换
创建存储Aurora-PostgreSQL凭证的密钥,并关联上述栈生成的轮换Lambda:
# 存储数据库凭证的密钥 resource "aws_secretsmanager_secret" "db_creds" { name = "aurora-pg-prod-credentials" description = "Aurora PostgreSQL production credentials" # 提前存入初始凭证(也可通过Secrets Manager控制台手动录入) secret_string = jsonencode({ username = "admin" password = "initial-strong-password" engine = "postgres" host = aws_rds_cluster.pg_cluster.endpoint port = 5432 dbname = "prod_db" }) } # 配置密钥轮换 resource "aws_secretsmanager_secret_rotation" "db_rotation" { secret_id = aws_secretsmanager_secret.db_creds.id rotation_lambda_arn = aws_serverlessapplicationrepository_cloudformation_stack.pg_rotation_stack.outputs["LambdaFunctionArn"] rotation_rules { automatically_after_days = 30 } }
3. 自定义权限配置(可选)
如果需要替换SAM栈默认权限,可手动创建IAM角色并附加最小权限策略:
resource "aws_iam_role" "rotation_role" { name = "aurora-pg-secret-rotation-role" assume_role_policy = jsonencode({ Version = "2012-10-17" Statement = [{ Action = "sts:AssumeRole" Effect = "Allow" Principal = { Service = "lambda.amazonaws.com" } }] }) } resource "aws_iam_role_policy_attachment" "rotation_basic_execution" { role = aws_iam_role.rotation_role.name policy_arn = "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole" } resource "aws_iam_role_policy" "rotation_custom" { name = "aurora-pg-rotation-custom-policy" role = aws_iam_role.rotation_role.id policy = jsonencode({ Version = "2012-10-17" Statement = [ { Effect = "Allow" Action = ["secretsmanager:GetSecretValue", "secretsmanager:PutSecretValue", "secretsmanager:UpdateSecretVersionStage"] Resource = aws_secretsmanager_secret.db_creds.arn }, { Effect = "Allow" Action = ["rds-db:connect", "rds:DescribeDBInstances"] Resource = [ "arn:aws:rds-db:${var.region}:${data.aws_caller_identity.current.account_id}:dbuser:${aws_rds_cluster.pg_cluster.id}/admin", "arn:aws:rds:${var.region}:${data.aws_caller_identity.current.account_id}:cluster:${aws_rds_cluster.pg_cluster.id}" ] } ] }) }
关键注意事项
- AWS Provider 5.62完全支持
aws_secretsmanager_secret_rotation和aws_serverlessapplicationrepository_cloudformation_stack资源,无版本兼容性问题 - 若Aurora集群部署在VPC内,必须为轮换Lambda配置对应VPC子网和安全组,确保Lambda能访问RDS实例
- 密钥的
secret_string必须包含username、password、engine、host等字段,否则轮换函数无法正常执行
内容的提问来源于stack exchange,提问作者s3-m-bocian
相关产品推荐
相关产品推荐

