跳至內容

Pass Credentials to EC2 Image Builder - Connecting to a Network Share

0

Hello,

Is there a way to allow EC2 Image Builder (using it for AWS Workspaces) to connect to a network share in a domain environment using maybe something like a service account? Of course, I don't mean to inject / store credentials in a Component, but rather try to securely pass them to EC2 IB in order to obtain files needed for a custom imaging process. Not sure if AWS Lambda is the route to go for that or something else, if it is possible.

I currently use an S3 bucket for the files for testing my pipeline builds, but the network share is being managed and that location is where the files would be updated when necessary. It would be beneficial to have these scripts always grab the recent files whenever the network share is updated.

Thank you.

已提問 3 個月前檢視次數 63 次

1 個回答
2

Yes, you can achieve this without using AWS Lambda. The AWS-recommended best practice for this scenario is to use AWS Secrets Manager in combination with the IAM role assigned to your builder instance.

Here is the straightforward approach to securely pass credentials without storing them in your Image Builder Component:

1. Store Credentials:

Save your domain service account credentials securely as a key-value pair (e.g., username and password) in AWS Secrets Manager.

2. Update IAM Permissions:

Go to the Infrastructure Configuration of your Image Builder pipeline and check the attached IAM Instance Profile. Add an IAM policy to this role that grants the secretsmanager:GetSecretValue permission (ideally restricted to the specific ARN of your newly created secret).

3. Fetch Dynamically in your Component:

In your custom Component document (using an ExecutePowerShell action), retrieve the secret at runtime into memory, map the drive, grab your files, and disconnect.

Here is an example using PowerShell for a Windows Component:


# 1. Fetch secret from AWS Secrets Manager

$Secret = (Get-SECSecretValue -SecretId "your-service-account-secret").SecretString | ConvertFrom-Json
$Password = $Secret.password | ConvertTo-SecureString -AsPlainText -Force
$Credential = New-Object System.Management.Automation.PSCredential ("YOURDOMAIN\$($Secret.username)", $Password)

# 2. Mount network share securely

New-PSDrive -Name "NetShare" -PSProvider FileSystem -Root "\\your-server\share-path" -Credential $Credential

# 3. Copy your required files

Copy-Item -Path "NetShare:\*" -Destination "C:\YourLocalBuildPath" -Recurse

# 4. Cleanup

Remove-PSDrive -Name "NetShare"

Note: Ensure that the VPC, Subnet, and Security Groups specified in your Infrastructure Configuration allow outbound traffic to your network share (specifically TCP Port 445 for SMB, routed via VPN/Direct Connect/Transit Gateway) and to AWS Secrets Manager (either via a NAT Gateway or a VPC Interface Endpoint for Secrets Manager).

專家

已回答 3 個月前

  • Thank you, Florian. This is exactly what I am looking for and I am eager to write up an implementation to test after I get those other dependancies in place.

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。