You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

非Azure生产环境中ASP.NET Core用户密钥存储的推荐方案是什么?

Secure Secret Management for .NET Core in Non-Azure Production Environments (e.g., AWS)

Great question! Since you're building a .NET Core project and need secure alternatives to Azure Key Vault for non-Azure environments like AWS, here are some practical, production-ready solutions tailored to your needs:

  • AWS Secrets Manager + .NET Core Configuration Provider
    AWS Secrets Manager is a fully managed service built for storing and rotating sensitive data like API keys, database credentials, and OAuth tokens. For .NET Core, you can use the official AWS configuration provider package Amazon.Extensions.Configuration.SecretsManager to integrate it directly into your app's configuration system.

    Example setup in Program.cs:

    var builder = WebApplication.CreateBuilder(args);
    // Add AWS Secrets Manager as a configuration source
    builder.Configuration.AddSecretsManager(
        secretName: "MyApp/Production/Secrets",
        options => {
            options.Region = Amazon.RegionEndpoint.USWest2;
        });
    
    // Access secrets just like regular config values
    var apiKey = builder.Configuration["ApiKey"];
    

    This lets you pull secrets dynamically without hardcoding, and AWS handles automatic secret rotation and fine-grained IAM-based access control.

  • AWS Systems Manager Parameter Store
    If you need a more cost-effective option (especially for non-rotating secrets or configuration parameters), AWS Systems Manager Parameter Store is a solid pick. It supports storing plaintext and encrypted parameters, and integrates seamlessly with .NET Core via the Amazon.Extensions.Configuration.SystemsManager package.

    You can load parameters by path to organize your configuration:

    builder.Configuration.AddSystemsManager(
        parameterPath: "/MyApp/Production/",
        reloadAfter: TimeSpan.FromMinutes(5)); // Auto-refresh config changes
    

    It works well with AWS IAM roles, so your app can access parameters without storing AWS access keys directly.

  • HashiCorp Vault (Cross-Cloud/On-Prem)
    For a truly cloud-agnostic solution that works across AWS, GCP, on-prem, or hybrid environments, HashiCorp Vault is an industry standard. It offers robust features like dynamic secret generation, identity-based authentication (including AWS IAM authentication for AWS workloads), and detailed access policies.

    You can integrate it with .NET Core using libraries like VaultSharp, which lets you fetch secrets programmatically or even set it up as a configuration source. This is ideal if you plan to deploy across multiple cloud providers or need advanced secret management capabilities.

  • Environment Variables (Simplified Approach)
    While not a dedicated secret manager, environment variables are a common and straightforward option for production, especially when paired with AWS deployment tools like ECS, EC2, or Lambda. .NET Core automatically reads environment variables into its configuration system, so you can inject secrets via your deployment pipeline instead of hardcoding them.

    To access a secret:

    var dbPassword = Environment.GetEnvironmentVariable("DB_PASSWORD");
    // Or via configuration
    var apiSecret = builder.Configuration["ApiSecret"];
    

    Just make sure to restrict access to these environment variables using AWS IAM roles and avoid exposing them in logs or deployment scripts.

Key Best Practices

  • Never hardcode secrets in your codebase or commit them to version control (use .NET Core's app secrets for development, as you explored earlier).
  • Prefer managed secret services over manual solutions—they handle encryption, rotation, and access control out of the box.
  • Use IAM roles or service accounts to grant your app access to secret managers, instead of embedding access keys in your application.

内容的提问来源于stack exchange,提问作者David S.

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 10:00:39