You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于AWS Secrets Manager轮换Lambda的VpcSecurityGroupIds用途及配置的疑问

Secrets Manager托管DocumentDB轮换Lambda:VpcSecurityGroupIds参数详解

核心作用

VpcSecurityGroupIds参数是同时配置托管轮换Lambda的网络权限,以及目标DocumentDB的入站信任关系,具体逻辑是:

  1. 为自动创建的轮换Lambda分配指定的安全组,让Lambda能在VPC内运行(必须配置才能让Lambda访问私有子网内的DocumentDB);
  2. 自动在目标DocumentDB的安全组中添加入站规则,允许来自这些Lambda安全组的27017端口流量(确保Lambda能连接数据库执行密码轮换)。

针对你的疑问逐一解答

1. 是否要将自定义数据库安全组MyCustomDocumentDBSecurityGroup关联给Lambda?

可以,但更合理的配置分两种场景:

  • 场景1:复用数据库安全组
    如果你把MyCustomDocumentDBSecurityGroup填入VpcSecurityGroupIds:

    • 轮换Lambda会被分配到这个安全组,继承组内的出站权限(默认安全组允许所有出站,满足Lambda连接27017的需求);
    • Secrets Manager会自动在MyCustomDocumentDBSecurityGroup中添加一条入站规则:允许来自该组本身的27017端口流量(因为Lambda和数据库同组,组内资源默认互信)。
      这种方式配置简单,适合小型环境或测试场景。
  • 场景2:使用独立Lambda安全组(更安全)
    创建一个单独的LambdaRotationSecurityGroup,仅配置:

    • 出站规则:允许到27017端口的流量(指向DocumentDB的安全组或VPC CIDR);
      然后将这个组填入VpcSecurityGroupIds:
    • Lambda会被分配到这个组,获得必要的出站权限;
    • Secrets Manager会自动在MyCustomDocumentDBSecurityGroup中添加入站规则,允许来自LambdaRotationSecurityGroup的27017流量。
      这种方式遵循最小权限原则,避免数据库安全组的权限过度开放。

2. 留空VpcSecurityGroupIds的影响

如果留空该参数,轮换Lambda会在VPC外的公共子网运行,此时:

  • 你的自定义数据库安全组MyCustomDocumentDBSecurityGroup会完全保留原配置,不会被修改;
  • 但Lambda无法访问私有子网内的DocumentDB(除非你为DocumentDB配置公网访问,且安全组允许互联网IP的27017流量)——这在生产环境中不推荐,因为存在安全风险。

3. 关于文档矛盾的解释

控制台文档提到“轮换函数与数据库使用相同VPC和安全组”是一种简化的推荐配置,适合快速部署;而评论建议使用单独安全组是从安全最佳实践出发的进阶配置。两者并不矛盾:

  • 同组配置:操作简单,无需额外维护安全组;
  • 独立安全组:权限更精细,降低不必要的攻击面。

示例CloudFormation片段

# 自定义数据库安全组
MyCustomDocumentDBSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: Allow DocumentDB inbound traffic
    VpcId: !Ref MyVPC
    SecurityGroupIngress:
      # 基础入站规则,可根据需求调整
      - IpProtocol: tcp
        FromPort: 27017
        ToPort: 27017
        CidrIp: !Ref MyVpcCidr

# 独立的Lambda轮换安全组(推荐)
LambdaRotationSecurityGroup:
  Type: AWS::EC2::SecurityGroup
  Properties:
    GroupDescription: Allow Lambda outbound to DocumentDB
    VpcId: !Ref MyVPC
    SecurityGroupEgress:
      - IpProtocol: tcp
        FromPort: 27017
        ToPort: 27017
        DestinationSecurityGroupId: !Ref MyCustomDocumentDBSecurityGroup

# Secrets Manager轮换配置
DocumentDBSecretRotation:
  Type: AWS::SecretsManager::RotationSchedule
  Properties:
    SecretId: !Ref DocumentDBSecret
    RotationLambdaARN: !GetAtt DocumentDBRotationLambda.Arn
    RotationRules:
      AutomaticallyAfterDays: 30
    HostedRotationLambda:
      Type: MongoDBSingleUser
      VpcSecurityGroupIds:
        - !Ref LambdaRotationSecurityGroup
      VpcSubnetIds: !Ref MyPrivateSubnets

内容的提问来源于stack exchange,提问作者Garret Wilson

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.25 17:37:17