You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何用Terraform实现基于AWS托管Lambda的Aurora-PostgreSQL密钥轮换?

能复现,Terraform 1.9 + AWS Provider 5.62完全支持该配置

AWS控制台的预构建密钥轮换模板本质是部署了AWS维护的SAM应用(对应PostgreSQL的是SecretsManagerRDSPostgreSQLRotationSingleUser),同时创建配套IAM角色和Lambda函数。用Terraform可以完全复现这一流程,核心是通过aws_secretsmanager_secret_rotation资源配置轮换逻辑,结合Serverless Application Repository部署官方轮换Lambda。

核心实现步骤

1. 部署官方轮换SAM应用

直接引用AWS Serverless Application Repository中的预构建轮换应用,这和控制台模板的逻辑完全一致:

resource "aws_serverlessapplicationrepository_cloudformation_stack" "pg_rotation_stack" {
  name             = "aurora-pg-secret-rotation"
  application_id   = "arn:aws:serverlessrepo:us-east-1:297356227824:applications/SecretsManagerRDSPostgreSQLRotationSingleUser"
  semantic_version = "1.1.2" # 可替换为最新版本

  parameters = {
    SecretId              = aws_secretsmanager_secret.db_creds.id
    VpcSecurityGroupIds   = aws_security_group.db_sg.id
    VpcSubnetIds          = join(",", aws_subnet.private.*.id)
    MasterSecretArn       = aws_secretsmanager_secret.db_creds.id # 单用户轮换模式下填自身
    RotationIntervalInDays = "30"
  }
}

该栈会自动生成轮换Lambda函数、IAM角色及必要权限,和控制台操作的输出完全一致。

2. 配置Secrets Manager密钥及轮换

创建存储Aurora-PostgreSQL凭证的密钥,并关联上述栈生成的轮换Lambda:

# 存储数据库凭证的密钥
resource "aws_secretsmanager_secret" "db_creds" {
  name        = "aurora-pg-prod-credentials"
  description = "Aurora PostgreSQL production credentials"

  # 提前存入初始凭证(也可通过Secrets Manager控制台手动录入)
  secret_string = jsonencode({
    username = "admin"
    password = "initial-strong-password"
    engine   = "postgres"
    host     = aws_rds_cluster.pg_cluster.endpoint
    port     = 5432
    dbname   = "prod_db"
  })
}

# 配置密钥轮换
resource "aws_secretsmanager_secret_rotation" "db_rotation" {
  secret_id           = aws_secretsmanager_secret.db_creds.id
  rotation_lambda_arn = aws_serverlessapplicationrepository_cloudformation_stack.pg_rotation_stack.outputs["LambdaFunctionArn"]
  
  rotation_rules {
    automatically_after_days = 30
  }
}

3. 自定义权限配置(可选)

如果需要替换SAM栈默认权限,可手动创建IAM角色并附加最小权限策略:

resource "aws_iam_role" "rotation_role" {
  name = "aurora-pg-secret-rotation-role"

  assume_role_policy = jsonencode({
    Version = "2012-10-17"
    Statement = [{
      Action = "sts:AssumeRole"
      Effect = "Allow"
      Principal = { Service = "lambda.amazonaws.com" }
    }]
  })
}

resource "aws_iam_role_policy_attachment" "rotation_basic_execution" {
  role       = aws_iam_role.rotation_role.name
  policy_arn = "arn:aws:iam::aws:policy/service-role/AWSLambdaBasicExecutionRole"
}

resource "aws_iam_role_policy" "rotation_custom" {
  name   = "aurora-pg-rotation-custom-policy"
  role   = aws_iam_role.rotation_role.id
  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect = "Allow"
        Action = ["secretsmanager:GetSecretValue", "secretsmanager:PutSecretValue", "secretsmanager:UpdateSecretVersionStage"]
        Resource = aws_secretsmanager_secret.db_creds.arn
      },
      {
        Effect = "Allow"
        Action = ["rds-db:connect", "rds:DescribeDBInstances"]
        Resource = [
          "arn:aws:rds-db:${var.region}:${data.aws_caller_identity.current.account_id}:dbuser:${aws_rds_cluster.pg_cluster.id}/admin",
          "arn:aws:rds:${var.region}:${data.aws_caller_identity.current.account_id}:cluster:${aws_rds_cluster.pg_cluster.id}"
        ]
      }
    ]
  })
}

关键注意事项

  • AWS Provider 5.62完全支持aws_secretsmanager_secret_rotation和aws_serverlessapplicationrepository_cloudformation_stack资源,无版本兼容性问题
  • 若Aurora集群部署在VPC内,必须为轮换Lambda配置对应VPC子网和安全组,确保Lambda能访问RDS实例
  • 密钥的secret_string必须包含username、password、engine、host等字段,否则轮换函数无法正常执行

内容的提问来源于stack exchange,提问作者s3-m-bocian

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.20 01:21:03