You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何编写Bash脚本批量将AWS Secrets Manager中的400个自定义类型机密从账户A复制到账户B

Got it, let's work through this problem step by step. Your current out.json is just a stack of separate JSON objects glued together, which isn't valid JSON that tools like jq can parse cleanly. Here's how to fix that and batch create all your secrets in Account B:

Step 1: Fix the out.json format first

Your original script appended each get-secret-value output directly to out.json, resulting in something like {...}{...}{...} — this isn't a valid JSON array. We need to convert it to a proper array so we can iterate through each secret easily.

Run this command to modify out.json into valid JSON:

sed -i '1s/^/[/; $s/$/]/; s/}{/},{/g' out.json

Breakdown of what this does:

  • 1s/^/[/: Adds a [ at the very start of the file to open the array
  • $s/$/]/: Adds a ] at the end of the file to close the array
  • s/}{/},{/g: Replaces every }{ (the boundary between two JSON objects) with },{ to properly separate entries in the array

Step 2: Batch create secrets in Account B

Now that out.json is a valid JSON array, we can use jq to loop through each secret entry and call the create-secret command. Here's a bash script to handle this:

#!/bin/bash

# Iterate over each secret object in the JSON array (one per line)
jq -c '.[]' out.json | while read -r secret_entry; do
    # Extract the original secret name from Account A
    secret_name=$(echo "$secret_entry" | jq -r '.Name')
    # Extract the actual secret content string
    secret_content=$(echo "$secret_entry" | jq -r '.SecretString')

    echo "Creating secret: $secret_name"
    # Run the create command for Account B
    aws secretsmanager create-secret \
        --name "$secret_name" \
        --secret-string "$secret_content" \
        # Uncomment the line below if you need to overwrite existing secrets (use with caution!)
        # --force-overwrite
done

Important Notes:

  • Account B Setup: Make sure your AWS CLI is configured to target Account B before running this script. You can use a named profile with --profile <YOUR_B_ACCOUNT_PROFILE> added to the aws command, or set the appropriate environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY).
  • Duplicate Secrets: If a secret with the same name already exists in Account B, the create-secret command will fail. If you intentionally want to overwrite existing secrets, uncomment the --force-overwrite flag — just double-check you're not replacing critical data.
  • Error Handling: For production use, add basic error handling to log failures. For example:
    if ! aws secretsmanager create-secret ...; then
        echo "Failed to create secret: $secret_name" >> secret_creation_errors.log
    fi
    
  • Binary Secrets: If any of your custom secrets use SecretBinary instead of SecretString, you'll need to adjust the script to handle base64 decoding and use the --secret-binary flag instead. But for most custom secrets, SecretString is the correct field.

内容的提问来源于stack exchange,提问作者HelloWorld

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.30 14:27:47