You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在CDK控制台日志中隐藏CfnOutput的敏感值?

问题描述

我在TypeScript CDK代码中使用CfnOutput输出敏感值,希望这些值不会显示在控制台日志中。我的代码实现如下:

const accessKey = new CfnAccessKey(this, 'testUserKey', {
  userName: testUser.userName,
});

const accessKeyId = new CfnOutput(this, 'accessKey', { value: accessKey.ref });
const attrSecretAccessKey = new CfnOutput(this, 'secretAccessKey', { value: accessKey.attrSecretAccessKey });

目前CDK会在日志中明文展示这些输出值,示例如下:

Outputs:
stagingConsulComponents.accessKey = ADGHHBAS26TGDRGV
stagingConsulComponents.secretAccessKey = JKGHDJhdskjhfzhfsdjdafhJHJdd

请问是否有办法阻止CDK在控制台日志中显示这些敏感值?

解决方案

在创建CfnOutput时添加sensitive: true属性,标记输出为敏感值,CDK就不会在控制台日志中明文显示该值,而是用占位符替代。

修改后的代码示例:

const accessKey = new CfnAccessKey(this, 'testUserKey', {
  userName: testUser.userName,
});

const accessKeyId = new CfnOutput(this, 'accessKey', { 
  value: accessKey.ref,
  sensitive: true
});
const attrSecretAccessKey = new CfnOutput(this, 'secretAccessKey', { 
  value: accessKey.attrSecretAccessKey,
  sensitive: true
});

添加该属性后,控制台日志的输出会变成:

Outputs:
stagingConsulComponents.accessKey = <sensitive>
stagingConsulComponents.secretAccessKey = <sensitive>

注意:该属性仅控制控制台日志的显示,敏感值仍会保存在CloudFormation输出中。通过AWS控制台或CLI工具查看时,CLI默认也会隐藏敏感值,需通过aws cloudformation describe-stacks配合--query和--output text参数才能获取明文。

内容的提问来源于stack exchange,提问作者KatKibo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.20 07:30:50