如何在CDK控制台日志中隐藏CfnOutput的敏感值?
问题描述
我在TypeScript CDK代码中使用CfnOutput输出敏感值,希望这些值不会显示在控制台日志中。我的代码实现如下:
const accessKey = new CfnAccessKey(this, 'testUserKey', { userName: testUser.userName, }); const accessKeyId = new CfnOutput(this, 'accessKey', { value: accessKey.ref }); const attrSecretAccessKey = new CfnOutput(this, 'secretAccessKey', { value: accessKey.attrSecretAccessKey });
目前CDK会在日志中明文展示这些输出值,示例如下:
Outputs: stagingConsulComponents.accessKey = ADGHHBAS26TGDRGV stagingConsulComponents.secretAccessKey = JKGHDJhdskjhfzhfsdjdafhJHJdd
请问是否有办法阻止CDK在控制台日志中显示这些敏感值?
解决方案
在创建CfnOutput时添加sensitive: true属性,标记输出为敏感值,CDK就不会在控制台日志中明文显示该值,而是用占位符替代。
修改后的代码示例:
const accessKey = new CfnAccessKey(this, 'testUserKey', { userName: testUser.userName, }); const accessKeyId = new CfnOutput(this, 'accessKey', { value: accessKey.ref, sensitive: true }); const attrSecretAccessKey = new CfnOutput(this, 'secretAccessKey', { value: accessKey.attrSecretAccessKey, sensitive: true });
添加该属性后,控制台日志的输出会变成:
Outputs: stagingConsulComponents.accessKey = <sensitive> stagingConsulComponents.secretAccessKey = <sensitive>
注意:该属性仅控制控制台日志的显示,敏感值仍会保存在CloudFormation输出中。通过AWS控制台或CLI工具查看时,CLI默认也会隐藏敏感值,需通过aws cloudformation describe-stacks配合--query和--output text参数才能获取明文。
内容的提问来源于stack exchange,提问作者KatKibo
相关产品推荐
相关产品推荐

