非Azure生产环境中ASP.NET Core用户密钥存储的推荐方案是什么?
Great question! Since you're building a .NET Core project and need secure alternatives to Azure Key Vault for non-Azure environments like AWS, here are some practical, production-ready solutions tailored to your needs:
AWS Secrets Manager + .NET Core Configuration Provider
AWS Secrets Manager is a fully managed service built for storing and rotating sensitive data like API keys, database credentials, and OAuth tokens. For .NET Core, you can use the official AWS configuration provider packageAmazon.Extensions.Configuration.SecretsManagerto integrate it directly into your app's configuration system.Example setup in
Program.cs:var builder = WebApplication.CreateBuilder(args); // Add AWS Secrets Manager as a configuration source builder.Configuration.AddSecretsManager( secretName: "MyApp/Production/Secrets", options => { options.Region = Amazon.RegionEndpoint.USWest2; }); // Access secrets just like regular config values var apiKey = builder.Configuration["ApiKey"];This lets you pull secrets dynamically without hardcoding, and AWS handles automatic secret rotation and fine-grained IAM-based access control.
AWS Systems Manager Parameter Store
If you need a more cost-effective option (especially for non-rotating secrets or configuration parameters), AWS Systems Manager Parameter Store is a solid pick. It supports storing plaintext and encrypted parameters, and integrates seamlessly with .NET Core via theAmazon.Extensions.Configuration.SystemsManagerpackage.You can load parameters by path to organize your configuration:
builder.Configuration.AddSystemsManager( parameterPath: "/MyApp/Production/", reloadAfter: TimeSpan.FromMinutes(5)); // Auto-refresh config changesIt works well with AWS IAM roles, so your app can access parameters without storing AWS access keys directly.
HashiCorp Vault (Cross-Cloud/On-Prem)
For a truly cloud-agnostic solution that works across AWS, GCP, on-prem, or hybrid environments, HashiCorp Vault is an industry standard. It offers robust features like dynamic secret generation, identity-based authentication (including AWS IAM authentication for AWS workloads), and detailed access policies.You can integrate it with .NET Core using libraries like
VaultSharp, which lets you fetch secrets programmatically or even set it up as a configuration source. This is ideal if you plan to deploy across multiple cloud providers or need advanced secret management capabilities.Environment Variables (Simplified Approach)
While not a dedicated secret manager, environment variables are a common and straightforward option for production, especially when paired with AWS deployment tools like ECS, EC2, or Lambda. .NET Core automatically reads environment variables into its configuration system, so you can inject secrets via your deployment pipeline instead of hardcoding them.To access a secret:
var dbPassword = Environment.GetEnvironmentVariable("DB_PASSWORD"); // Or via configuration var apiSecret = builder.Configuration["ApiSecret"];Just make sure to restrict access to these environment variables using AWS IAM roles and avoid exposing them in logs or deployment scripts.
Key Best Practices
- Never hardcode secrets in your codebase or commit them to version control (use .NET Core's app secrets for development, as you explored earlier).
- Prefer managed secret services over manual solutions—they handle encryption, rotation, and access control out of the box.
- Use IAM roles or service accounts to grant your app access to secret managers, instead of embedding access keys in your application.
内容的提问来源于stack exchange,提问作者David S.

