Skip to content

Commit

Permalink
add oracle password rotation
Browse files Browse the repository at this point in the history
  • Loading branch information
badra001 committed Feb 27, 2025
1 parent bff1a7b commit a6aea7a
Showing 1 changed file with 29 additions and 0 deletions.
29 changes: 29 additions & 0 deletions aws/proposals/oracle-secret-rotation/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
# Oracle Password Secret Rotation

Format:

```script
/db/{rds-instance-name}/{database-name}/{username}
```

Tags:

* rds_username = JBID
* rds_fqdn = DNS name of RDS instance

Rotation:

* per-user (meaning an original passsword needs to be provided or an admin sets it on creation of the secret)
* daily at say 10pm M-F

Permission:

Grant access to the secret by username from SSO, plus and admins (inf-terraform, inf-admin-t*)

Script:

Create script (python, powershell) to pull secret with AWS CLI or SDK:

get-oracle-password --rds-instance NAME --database NAME --username NAME

outputs password

0 comments on commit a6aea7a

Please sign in to comment.