Managing datasource credentials with AWS Secrets Manager
Integrate your GuardiumĀ®
system with the Amazon Web Services (AWS) Secrets Manager to securely store, manage, rotate, and
retrieve credentials for your datasources that use the Amazon Relational Database Service
(RDS).
Gathering required information from AWS Secrets Manager Obtain the AWS Secrets Manager configuration information from the AWS management console.Creating a secret user Create a database user and assign credentials.Creating a secret key Create and configure a secret name and secret access key for the secret user on the AWS management console. Selecting the authentication type and setting up roles Guardium supports three authentication types to connect to the AWS Secrets Manager and AWS database services - Security Credentials, IAM Role, and IAM Instance Profile. Set up and configure the authentication type for your Guardium datasource. Configuring the AWS Secrets Manager on your Guardium system Configure the AWS Secrets Manager on your Guardium system. Each secret user must be configured on your Guardium system to access the AWS Secrets Manager .Defining Guardium datasources to access AWS Secret Manager Configure the datasources on your Guardium system for automatic password provisioning using the AWS Secrets Manager . You can create a new datasource definition or edit an existing definition.