├── docs ├── drawio │ ├── stub │ └── raw.drawio ├── img │ ├── test_button.png │ ├── test_trigger.png │ ├── rbac_actor_flow.png │ ├── rbac_user_example.png │ ├── consumer_log_output.png │ ├── outsider_log_output.png │ ├── producer_log_output.png │ ├── architecture_diagram_no_flow.png │ └── architecture_diagram_with_flow.png └── architecture.md ├── lib ├── lambda │ ├── requirements.txt │ ├── lib │ │ └── redis_module │ │ │ └── redis_py.zip │ ├── scripts │ │ └── redis_rbac.yml │ └── redis_connect.py ├── redis-rbac-secret-manager.ts └── redis-rbac-stack.ts ├── .npmignore ├── jest.config.js ├── .gitignore ├── CODE_OF_CONDUCT.md ├── tsconfig.json ├── package.json ├── LICENSE ├── bin └── redis-rbac.ts ├── cdk.json ├── README.md ├── test └── redis-rbac.test.ts └── CONTRIBUTING.md /docs/drawio/stub: -------------------------------------------------------------------------------- 1 | -------------------------------------------------------------------------------- /lib/lambda/requirements.txt: -------------------------------------------------------------------------------- 1 | redis -------------------------------------------------------------------------------- /.npmignore: -------------------------------------------------------------------------------- 1 | *.ts 2 | !*.d.ts 3 | 4 | # CDK asset staging directory 5 | .cdk.staging 6 | cdk.out 7 | -------------------------------------------------------------------------------- /docs/img/test_button.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/test_button.png -------------------------------------------------------------------------------- /docs/img/test_trigger.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/test_trigger.png -------------------------------------------------------------------------------- /docs/img/rbac_actor_flow.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/rbac_actor_flow.png -------------------------------------------------------------------------------- /docs/img/rbac_user_example.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/rbac_user_example.png -------------------------------------------------------------------------------- /docs/img/consumer_log_output.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/consumer_log_output.png -------------------------------------------------------------------------------- /docs/img/outsider_log_output.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/outsider_log_output.png -------------------------------------------------------------------------------- /docs/img/producer_log_output.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/producer_log_output.png -------------------------------------------------------------------------------- /lib/lambda/lib/redis_module/redis_py.zip: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/lib/lambda/lib/redis_module/redis_py.zip -------------------------------------------------------------------------------- /docs/img/architecture_diagram_no_flow.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/architecture_diagram_no_flow.png -------------------------------------------------------------------------------- /docs/img/architecture_diagram_with_flow.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/aws-samples/aws-cdk-elasticache-redis-iam-rbac/HEAD/docs/img/architecture_diagram_with_flow.png -------------------------------------------------------------------------------- /lib/lambda/scripts/redis_rbac.yml: -------------------------------------------------------------------------------- 1 | aws elasticache create-user \ 2 | --user-id "mock_application_user" \ 3 | --user-name "mock_app_user" \ 4 | --engine "REDIS" \ 5 | --passwords "a-str0ng-pa))word" \ 6 | --access-string "off +get ~keys*" -------------------------------------------------------------------------------- /jest.config.js: -------------------------------------------------------------------------------- 1 | // Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 2 | // SPDX-License-Identifier: MIT-0 3 | module.exports = { 4 | roots: ['/test'], 5 | testMatch: ['**/*.test.ts'], 6 | transform: { 7 | '^.+\\.tsx?$': 'ts-jest' 8 | } 9 | }; 10 | -------------------------------------------------------------------------------- /.gitignore: -------------------------------------------------------------------------------- 1 | *.js 2 | !jest.config.js 3 | *.d.ts 4 | node_modules 5 | 6 | # CDK asset staging directory 7 | .cdk.staging 8 | cdk.out 9 | drawio/ 10 | scripts/ 11 | 12 | lib/lambda/lib/redis_module 13 | .DS_Store 14 | dump.rdb 15 | mock_app.zip 16 | rbac_cr.zip 17 | package-lock.json 18 | cfn*.txt 19 | -------------------------------------------------------------------------------- /CODE_OF_CONDUCT.md: -------------------------------------------------------------------------------- 1 | ## Code of Conduct 2 | This project has adopted the [Amazon Open Source Code of Conduct](https://aws.github.io/code-of-conduct). 3 | For more information see the [Code of Conduct FAQ](https://aws.github.io/code-of-conduct-faq) or contact 4 | opensource-codeofconduct@amazon.com with any additional questions or comments. 5 | -------------------------------------------------------------------------------- /tsconfig.json: -------------------------------------------------------------------------------- 1 | { 2 | "compilerOptions": { 3 | "target": "ES2018", 4 | "module": "commonjs", 5 | "lib": ["es2018"], 6 | "declaration": true, 7 | "strict": true, 8 | "noImplicitAny": true, 9 | "strictNullChecks": true, 10 | "noImplicitThis": true, 11 | "alwaysStrict": true, 12 | "noUnusedLocals": false, 13 | "noUnusedParameters": false, 14 | "noImplicitReturns": true, 15 | "noFallthroughCasesInSwitch": false, 16 | "inlineSourceMap": true, 17 | "inlineSources": true, 18 | "experimentalDecorators": true, 19 | "strictPropertyInitialization": false, 20 | "typeRoots": ["./node_modules/@types"] 21 | }, 22 | "exclude": ["cdk.out"] 23 | } 24 | -------------------------------------------------------------------------------- /package.json: -------------------------------------------------------------------------------- 1 | { 2 | "name": "redis-rbac", 3 | "version": "0.1.0", 4 | "bin": { 5 | "redis-rbac": "bin/redis-rbac.js" 6 | }, 7 | "scripts": { 8 | "build": "tsc", 9 | "zip": "./build_zips.sh", 10 | "watch": "tsc -w", 11 | "test": "jest", 12 | "cdk": "cdk" 13 | }, 14 | "devDependencies": { 15 | "@types/jest": "^27.5.2", 16 | "@types/node": "10.17.27", 17 | "@types/prettier": "2.6.0", 18 | "jest": "^27.5.1", 19 | "ts-jest": "^27.1.4", 20 | "aws-cdk": "2.43.1", 21 | "ts-node": "^10.9.1", 22 | "typescript": "~3.9.7" 23 | }, 24 | "dependencies": { 25 | "aws-cdk-lib": "2.43.1", 26 | "constructs": "^10.0.0", 27 | "source-map-support": "^0.5.21" 28 | } 29 | } 30 | -------------------------------------------------------------------------------- /LICENSE: -------------------------------------------------------------------------------- 1 | Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 2 | 3 | Permission is hereby granted, free of charge, to any person obtaining a copy of 4 | this software and associated documentation files (the "Software"), to deal in 5 | the Software without restriction, including without limitation the rights to 6 | use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of 7 | the Software, and to permit persons to whom the Software is furnished to do so. 8 | 9 | THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR 10 | IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS 11 | FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR 12 | COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER 13 | IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN 14 | CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. 15 | 16 | -------------------------------------------------------------------------------- /bin/redis-rbac.ts: -------------------------------------------------------------------------------- 1 | #!/usr/bin/env node 2 | /* 3 | * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 4 | * SPDX-License-Identifier: MIT-0 5 | * 6 | * Permission is hereby granted, free of charge, to any person obtaining a copy of this 7 | * software and associated documentation files (the "Software"), to deal in the Software 8 | * without restriction, including without limitation the rights to use, copy, modify, 9 | * merge, publish, distribute, sublicense, and/or sell copies of the Software, and to 10 | * permit persons to whom the Software is furnished to do so. 11 | * 12 | * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, 13 | * INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A 14 | * PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT 15 | * HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION 16 | * OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE 17 | * SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. 18 | */ 19 | 20 | import 'source-map-support/register'; 21 | import * as cdk from 'aws-cdk-lib'; 22 | import { RedisRbacStack } from '../lib/redis-rbac-stack'; 23 | 24 | const app = new cdk.App(); 25 | new RedisRbacStack(app, 'RedisRbacStack'); 26 | -------------------------------------------------------------------------------- /cdk.json: -------------------------------------------------------------------------------- 1 | { 2 | "app": "npx ts-node --prefer-ts-exts bin/redis-rbac.ts", 3 | "watch": { 4 | "include": [ 5 | "**" 6 | ], 7 | "exclude": [ 8 | "README.md", 9 | "cdk*.json", 10 | "**/*.d.ts", 11 | "**/*.js", 12 | "tsconfig.json", 13 | "package*.json", 14 | "yarn.lock", 15 | "node_modules", 16 | "test" 17 | ] 18 | }, 19 | "context": { 20 | "@aws-cdk/aws-apigateway:usagePlanKeyOrderInsensitiveId": true, 21 | "@aws-cdk/core:stackRelativeExports": true, 22 | "@aws-cdk/aws-rds:lowercaseDbIdentifier": true, 23 | "@aws-cdk/aws-lambda:recognizeVersionProps": true, 24 | "@aws-cdk/aws-lambda:recognizeLayerVersion": true, 25 | "@aws-cdk/aws-cloudfront:defaultSecurityPolicyTLSv1.2_2021": true, 26 | "@aws-cdk-containers/ecs-service-extensions:enableDefaultLogDriver": true, 27 | "@aws-cdk/aws-ec2:uniqueImdsv2TemplateName": true, 28 | "@aws-cdk/core:checkSecretUsage": true, 29 | "@aws-cdk/aws-iam:minimizePolicies": true, 30 | "@aws-cdk/aws-ecs:arnFormatIncludesClusterName": true, 31 | "@aws-cdk/core:validateSnapshotRemovalPolicy": true, 32 | "@aws-cdk/aws-codepipeline:crossAccountKeyAliasStackSafeResourceName": true, 33 | "@aws-cdk/aws-s3:createDefaultLoggingPolicy": true, 34 | "@aws-cdk/aws-sns-subscriptions:restrictSqsDescryption": true, 35 | "@aws-cdk/core:target-partitions": [ 36 | "aws", 37 | "aws-cn" 38 | ] 39 | }, 40 | "profile": "replace_with_profile_name" 41 | } 42 | -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- 1 | # Managing ElastiCache Redis access with Redis RBAC, AWS SecretsManager and AWS IAM 2 | 3 | This project demonstrates how to manage access to ElastiCache Redis by storing Redis RBAC username and passwords in AWS Secrets Manager. Granting or denying access to the secret will by proxy grant or deny access to Redis via RBAC. 4 | 5 | This project creates an ElastiCache Redis Replication group, IAM roles, Lambdas, Secrets and ElastiCache RBAC users and user groups. 6 | 7 | Details on the architecture can be found [here](docs/architecture.md) 8 | 9 | ## Installing CDK 10 | 11 | This project uses the AWS Cloud Development Kit (CDK). You can find instructions on installing CDK [here](https://docs.aws.amazon.com/cdk/latest/guide/getting_started.html#getting_started_install) 12 | 13 | ## How to build and deploy 14 | 15 | 1. Run `npm install` to install the node dependencies for the project 16 | 1. You may need to run `cdk bootstrap aws:///` to initialize the region to use CDK 17 | 1. Build the zip files which contain lambda functions by calling `npm run-script zip` 18 | 1. Deploy the project by calling `cdk deploy` 19 | 20 | ## Useful commands 21 | 22 | - `npm run-script zip` bundle lambda functions into zip files 23 | - `npm run build` compile typescript to js 24 | - `npm run watch` watch for changes and compile 25 | - `npm run test` perform the jest unit tests 26 | - `cdk deploy` deploy this stack to your default AWS account/region 27 | - `cdk diff` compare deployed stack with current state 28 | - `cdk synth` emits the synthesized CloudFormation template 29 | 30 | ## License 31 | 32 | This library is licensed under the MIT-0 License. See the [LICENSE](/architecture.md) file. 33 | -------------------------------------------------------------------------------- /test/redis-rbac.test.ts: -------------------------------------------------------------------------------- 1 | /* 2 | * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 3 | * SPDX-License-Identifier: MIT-0 4 | * 5 | * Permission is hereby granted, free of charge, to any person obtaining a copy of this 6 | * software and associated documentation files (the "Software"), to deal in the Software 7 | * without restriction, including without limitation the rights to use, copy, modify, 8 | * merge, publish, distribute, sublicense, and/or sell copies of the Software, and to 9 | * permit persons to whom the Software is furnished to do so. 10 | * 11 | * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, 12 | * INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A 13 | * PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT 14 | * HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION 15 | * OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE 16 | * SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. 17 | */ 18 | 19 | 20 | // import * as cdk from 'aws-cdk-lib'; 21 | // import { Template } from 'aws-cdk-lib/assertions'; 22 | // import * as Test from '../lib/test-stack'; 23 | 24 | // example test. To run these tests, uncomment this file along with the 25 | // example resource in lib/test-stack.ts 26 | test('SQS Queue Created', () => { 27 | // const app = new cdk.App(); 28 | // // WHEN 29 | // const stack = new Test.TestStack(app, 'MyTestStack'); 30 | // // THEN 31 | // const template = Template.fromStack(stack); 32 | 33 | // template.hasResourceProperties('AWS::SQS::Queue', { 34 | // VisibilityTimeout: 300 35 | // }); 36 | }); 37 | -------------------------------------------------------------------------------- /lib/lambda/redis_connect.py: -------------------------------------------------------------------------------- 1 | # Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 2 | # SPDX-License-Identifier: MIT-0 3 | # 4 | # Permission is hereby granted, free of charge, to any person obtaining a copy of this 5 | # software and associated documentation files (the "Software"), to deal in the Software 6 | # without restriction, including without limitation the rights to use, copy, modify, 7 | # merge, publish, distribute, sublicense, and/or sell copies of the Software, and to 8 | # permit persons to whom the Software is furnished to do so. 9 | # 10 | # THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, 11 | # INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A 12 | # PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT 13 | # HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION 14 | # OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE 15 | # SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. 16 | 17 | import redis 18 | import os 19 | import boto3 20 | import json 21 | from datetime import datetime 22 | 23 | def lambda_handler(event, context): 24 | client = boto3.client('secretsmanager') 25 | response = client.get_secret_value( 26 | SecretId=os.environ['secret_arn'] 27 | ) 28 | 29 | secret = json.loads(response['SecretString']) 30 | 31 | redis_server = redis.Redis( 32 | host=os.environ['redis_endpoint'], 33 | port=os.environ['redis_port'], 34 | username=secret['username'], 35 | password=secret['password'], 36 | ssl=True) 37 | 38 | try: 39 | time_now = datetime.now().strftime("%d/%m/%Y %H:%M:%S") 40 | redis_server.set("time", time_now) 41 | print ("Successfully set key 'time' to "+time_now) 42 | except Exception as e: 43 | print ("Exception trying to SET entry "+str(e)) 44 | 45 | try: 46 | result = redis_server.get("time") 47 | print ("Successfully retrieved key 'time' "+str(result)) 48 | except Exception as e: 49 | print ("Exception trying to GET entry "+str(e)) 50 | 51 | 52 | -------------------------------------------------------------------------------- /CONTRIBUTING.md: -------------------------------------------------------------------------------- 1 | # Contributing Guidelines 2 | 3 | Thank you for your interest in contributing to our project. Whether it's a bug report, new feature, correction, or additional 4 | documentation, we greatly value feedback and contributions from our community. 5 | 6 | Please read through this document before submitting any issues or pull requests to ensure we have all the necessary 7 | information to effectively respond to your bug report or contribution. 8 | 9 | 10 | ## Reporting Bugs/Feature Requests 11 | 12 | We welcome you to use the GitHub issue tracker to report bugs or suggest features. 13 | 14 | When filing an issue, please check existing open, or recently closed, issues to make sure somebody else hasn't already 15 | reported the issue. Please try to include as much information as you can. Details like these are incredibly useful: 16 | 17 | * A reproducible test case or series of steps 18 | * The version of our code being used 19 | * Any modifications you've made relevant to the bug 20 | * Anything unusual about your environment or deployment 21 | 22 | 23 | ## Contributing via Pull Requests 24 | Contributions via pull requests are much appreciated. Before sending us a pull request, please ensure that: 25 | 26 | 1. You are working against the latest source on the *main* branch. 27 | 2. You check existing open, and recently merged, pull requests to make sure someone else hasn't addressed the problem already. 28 | 3. You open an issue to discuss any significant work - we would hate for your time to be wasted. 29 | 30 | To send us a pull request, please: 31 | 32 | 1. Fork the repository. 33 | 2. Modify the source; please focus on the specific change you are contributing. If you also reformat all the code, it will be hard for us to focus on your change. 34 | 3. Ensure local tests pass. 35 | 4. Commit to your fork using clear commit messages. 36 | 5. Send us a pull request, answering any default questions in the pull request interface. 37 | 6. Pay attention to any automated CI failures reported in the pull request, and stay involved in the conversation. 38 | 39 | GitHub provides additional document on [forking a repository](https://help.github.com/articles/fork-a-repo/) and 40 | [creating a pull request](https://help.github.com/articles/creating-a-pull-request/). 41 | 42 | 43 | ## Finding contributions to work on 44 | Looking at the existing issues is a great way to find something to contribute on. As our projects, by default, use the default GitHub issue labels (enhancement/bug/duplicate/help wanted/invalid/question/wontfix), looking at any 'help wanted' issues is a great place to start. 45 | 46 | 47 | ## Code of Conduct 48 | This project has adopted the [Amazon Open Source Code of Conduct](https://aws.github.io/code-of-conduct). 49 | For more information see the [Code of Conduct FAQ](https://aws.github.io/code-of-conduct-faq) or contact 50 | opensource-codeofconduct@amazon.com with any additional questions or comments. 51 | 52 | 53 | ## Security issue notifications 54 | If you discover a potential security issue in this project we ask that you notify AWS/Amazon Security via our [vulnerability reporting page](http://aws.amazon.com/security/vulnerability-reporting/). Please do **not** create a public github issue. 55 | 56 | 57 | ## Licensing 58 | 59 | See the [LICENSE](LICENSE) file for our project's licensing. We will ask you to confirm the licensing of your contribution. 60 | -------------------------------------------------------------------------------- /lib/redis-rbac-secret-manager.ts: -------------------------------------------------------------------------------- 1 | /* 2 | * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 3 | * SPDX-License-Identifier: MIT-0 4 | * 5 | * Permission is hereby granted, free of charge, to any person obtaining a copy of this 6 | * software and associated documentation files (the "Software"), to deal in the Software 7 | * without restriction, including without limitation the rights to use, copy, modify, 8 | * merge, publish, distribute, sublicense, and/or sell copies of the Software, and to 9 | * permit persons to whom the Software is furnished to do so. 10 | * 11 | * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, 12 | * INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A 13 | * PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT 14 | * HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION 15 | * OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE 16 | * SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. 17 | */ 18 | 19 | import * as cdk from 'aws-cdk-lib'; 20 | import { 21 | aws_kms as kms, 22 | aws_iam as iam, 23 | aws_elasticache as elasticache, 24 | aws_secretsmanager as secretsmanager} from 'aws-cdk-lib'; 25 | import { Construct } from 'constructs'; 26 | 27 | export interface RedisRbacUserProps { 28 | redisUserName: string; 29 | redisUserId: string; 30 | accessString?: string; 31 | kmsKey?: kms.Key; 32 | principals?: iam.IPrincipal[] 33 | } 34 | 35 | 36 | export class RedisRbacUser extends Construct { 37 | public readonly response: string; 38 | 39 | private rbacUserSecret: secretsmanager.Secret; 40 | private secretResourcePolicyStatement: iam.PolicyStatement; 41 | private rbacUserName: string; 42 | private rbacUserId: string; 43 | private kmsKey: kms.Key; 44 | 45 | public getSecret(): secretsmanager.Secret { 46 | return this.rbacUserSecret; 47 | } 48 | 49 | public getUserName(): string { 50 | return this.rbacUserName; 51 | } 52 | 53 | public getUserId(): string{ 54 | return this.rbacUserId; 55 | } 56 | 57 | public getKmsKey(): kms.Key { 58 | return this.kmsKey; 59 | } 60 | 61 | public grantReadSecret(principal: iam.IPrincipal){ 62 | if (this.secretResourcePolicyStatement == null) { 63 | this.secretResourcePolicyStatement = new iam.PolicyStatement({ 64 | effect: iam.Effect.ALLOW, 65 | actions: ['secretsmanager:DescribeSecret', 'secretsmanager:GetSecretValue'], 66 | resources: [this.rbacUserSecret.secretArn], 67 | principals: [principal] 68 | }) 69 | 70 | this.rbacUserSecret.addToResourcePolicy(this.secretResourcePolicyStatement) 71 | 72 | } else { 73 | this.secretResourcePolicyStatement.addPrincipals(principal) 74 | } 75 | this.kmsKey.grantDecrypt(principal); 76 | this.rbacUserSecret.grantRead(principal) 77 | } 78 | 79 | constructor(scope: Construct, id: string, props: RedisRbacUserProps) { 80 | super(scope, id); 81 | 82 | this.rbacUserId = props.redisUserId 83 | this.rbacUserName = props.redisUserName 84 | 85 | if (!props.kmsKey) { 86 | this.kmsKey = new kms.Key(this, 'kmsForSecret', { 87 | alias: 'redisRbacUser/'+this.rbacUserName, 88 | enableKeyRotation: true 89 | }); 90 | } else { 91 | this.kmsKey = props.kmsKey; 92 | } 93 | 94 | this.rbacUserSecret = new secretsmanager.Secret(this, 'secret', { 95 | generateSecretString: { 96 | secretStringTemplate: JSON.stringify({ username: props.redisUserName }), 97 | generateStringKey: 'password', 98 | excludeCharacters: '@%*()_+=`~{}|[]\\:";\'?,./' 99 | }, 100 | encryptionKey: this.kmsKey 101 | }); 102 | 103 | const user = new elasticache.CfnUser(this, 'redisuser', { 104 | engine: 'redis', 105 | userName: props.redisUserName, 106 | accessString: props.accessString? props.accessString : "off +get ~keys*", 107 | userId: props.redisUserId, 108 | passwords: [this.rbacUserSecret.secretValueFromJson('password').unsafeUnwrap()] 109 | }) 110 | 111 | user.node.addDependency(this.rbacUserSecret) 112 | 113 | if(props.principals){ 114 | props.principals.forEach( (item) => { 115 | this.grantReadSecret(item) 116 | }); 117 | } 118 | 119 | } 120 | 121 | } 122 | -------------------------------------------------------------------------------- /lib/redis-rbac-stack.ts: -------------------------------------------------------------------------------- 1 | /* 2 | * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 3 | * SPDX-License-Identifier: MIT-0 4 | * 5 | * Permission is hereby granted, free of charge, to any person obtaining a copy of this 6 | * software and associated documentation files (the "Software"), to deal in the Software 7 | * without restriction, including without limitation the rights to use, copy, modify, 8 | * merge, publish, distribute, sublicense, and/or sell copies of the Software, and to 9 | * permit persons to whom the Software is furnished to do so. 10 | * 11 | * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, 12 | * INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A 13 | * PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT 14 | * HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION 15 | * OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE 16 | * SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. 17 | */ 18 | 19 | 20 | import * as cdk from 'aws-cdk-lib'; 21 | import { 22 | aws_ec2 as ec2, 23 | aws_kms as kms, 24 | aws_iam as iam, 25 | aws_elasticache as elasticache, 26 | aws_lambda as lambda, 27 | aws_secretsmanager as secretsmanager} from 'aws-cdk-lib'; 28 | import { Construct } from 'constructs'; 29 | import path = require('path'); 30 | import { RedisRbacUser } from "./redis-rbac-secret-manager"; 31 | 32 | import fs = require('fs'); 33 | 34 | import { setFlagsFromString } from 'v8'; 35 | 36 | 37 | export class RedisRbacStack extends cdk.Stack { 38 | 39 | constructor(scope: Construct, id: string, props?: cdk.StackProps) { 40 | super(scope, id, props); 41 | 42 | // ----------------------------------------------------------------------------------------------------------- 43 | // This constructor will deploy resources required to link ElastiCache Redis, with SecretsManager and IAM 44 | // ----------------------------------------------------------------------------------------------------------- 45 | // Steps: 46 | // Step 1) create a VPC into which the ElastiCache replication group will be placed 47 | // Step 2) create Redis RBAC users 48 | // a) one secret in Secrets Manager will be created for each 49 | // Step 3) create IAM roles and grant them read access to the appropriate secret 50 | // Step 4) create an ElastiCache Redis replication group 51 | // Step 5) create test functions 52 | 53 | let producerName = 'producer' 54 | let consumerName = 'consumer' 55 | let noAccessName = 'outsider' 56 | let elasticacheReplicationGroupName = 'RedisReplicationGroup' 57 | 58 | // ------------------------------------------------------------------------------------ 59 | // Step 1) Create a VPC into which the ElastiCache replication group will be placed 60 | // a) only private subnets will be used 61 | // b) a Secrets Manager VPC endpoint will be added to allow access to Secrets Manager 62 | // ------------------------------------------------------------------------------------ 63 | 64 | const vpc = new ec2.Vpc(this, "Vpc", { 65 | subnetConfiguration: [ 66 | { 67 | cidrMask: 24, 68 | name: 'Isolated', 69 | subnetType: ec2.SubnetType.PRIVATE_ISOLATED, 70 | } 71 | ] 72 | }); 73 | 74 | const flowLog = new ec2.FlowLog(this, 'VpcFlowLog', { 75 | resourceType: ec2.FlowLogResourceType.fromVpc(vpc) 76 | }) 77 | 78 | const lambdaSecurityGroup = new ec2.SecurityGroup(this, 'LambdaSG', { 79 | vpc: vpc, 80 | description: 'SecurityGroup into which Lambdas will be deployed', 81 | allowAllOutbound: false 82 | }); 83 | 84 | const secretsManagerVpcEndpointSecurityGroup = new ec2.SecurityGroup(this, 'SecretsManagerVPCeSG', { 85 | vpc: vpc, 86 | description: 'SecurityGroup for the VPC Endpoint Secrets Manager', 87 | allowAllOutbound: false, 88 | 89 | }); 90 | 91 | secretsManagerVpcEndpointSecurityGroup.connections.allowFrom(lambdaSecurityGroup, ec2.Port.tcp(443)); 92 | 93 | const secretsManagerEndpoint = vpc.addInterfaceEndpoint('SecretsManagerEndpoint', { 94 | service: ec2.InterfaceVpcEndpointAwsService.SECRETS_MANAGER, 95 | subnets: { 96 | subnetType: ec2.SubnetType.PRIVATE_ISOLATED 97 | }, 98 | open: false, 99 | securityGroups: [secretsManagerVpcEndpointSecurityGroup] 100 | }); 101 | 102 | const ecSecurityGroup = new ec2.SecurityGroup(this, 'ElastiCacheSG', { 103 | vpc: vpc, 104 | description: 'SecurityGroup associated with the ElastiCache Redis Cluster', 105 | allowAllOutbound: false, 106 | }); 107 | 108 | ecSecurityGroup.connections.allowFrom(lambdaSecurityGroup, ec2.Port.tcp(6379), 'Redis ingress 6379'); 109 | ecSecurityGroup.connections.allowTo(lambdaSecurityGroup, ec2.Port.tcp(6379), 'Redis egress 6379'); 110 | 111 | // ------------------------------------------------------------------------------------ 112 | // Step 2) Create IAM roles 113 | // a) each IAM role will be assumed by a lambda function 114 | // b) each IAM role will be granted read and decrypt permissions to a matching secret 115 | // ------------------------------------------------------------------------------------ 116 | const producerRole = new iam.Role(this, producerName+'Role', { 117 | assumedBy: new iam.ServicePrincipal('lambda.amazonaws.com'), 118 | description: 'Role to be assumed by producer lambda', 119 | }); 120 | 121 | producerRole.addManagedPolicy(iam.ManagedPolicy.fromAwsManagedPolicyName("service-role/AWSLambdaBasicExecutionRole")); 122 | producerRole.addManagedPolicy(iam.ManagedPolicy.fromAwsManagedPolicyName("service-role/AWSLambdaVPCAccessExecutionRole")); 123 | 124 | 125 | const consumerRole = new iam.Role(this, consumerName+'Role', { 126 | assumedBy: new iam.ServicePrincipal('lambda.amazonaws.com'), 127 | description: 'Role to be assumed by mock application lambda', 128 | }); 129 | consumerRole.addManagedPolicy(iam.ManagedPolicy.fromAwsManagedPolicyName("service-role/AWSLambdaBasicExecutionRole")); 130 | consumerRole.addManagedPolicy(iam.ManagedPolicy.fromAwsManagedPolicyName("service-role/AWSLambdaVPCAccessExecutionRole")); 131 | 132 | 133 | const noAccessRole = new iam.Role(this, noAccessName+'Role', { 134 | assumedBy: new iam.ServicePrincipal('lambda.amazonaws.com'), 135 | description: 'Role to be assumed by mock application lambda', 136 | }); 137 | noAccessRole.addManagedPolicy(iam.ManagedPolicy.fromAwsManagedPolicyName("service-role/AWSLambdaBasicExecutionRole")); 138 | noAccessRole.addManagedPolicy(iam.ManagedPolicy.fromAwsManagedPolicyName("service-role/AWSLambdaVPCAccessExecutionRole")); 139 | 140 | 141 | // ------------------------------------------------------------------------------------ 142 | // Step 3) Create Redis RBAC users 143 | // a) access strings will dictate operations that can be performed 144 | // b) RedisRbacUser is a class defined in redis-rbac-secret-manager.ts 145 | // c) RedisRbacUser is composed of an AWS::ElastiCache::User and a Secret 146 | // ------------------------------------------------------------------------------------ 147 | const commonKmsKey = new kms.Key(this, 'commonCredentialKey', { 148 | alias: 'redisRbacUser/common', 149 | enableKeyRotation: true 150 | }); 151 | 152 | const producerRbacUser = new RedisRbacUser(this, producerName+'RBAC', { 153 | redisUserName: producerName, 154 | redisUserId: producerName, 155 | accessString: 'on ~* -@all +SET', 156 | kmsKey: commonKmsKey, 157 | principals: [producerRole] 158 | }); 159 | 160 | const consumerRbacUser = new RedisRbacUser(this, consumerName+'RBAC', { 161 | redisUserName: 'consumer', 162 | redisUserId: 'consumer', 163 | accessString: 'on ~* -@all +GET', 164 | kmsKey: commonKmsKey, 165 | principals: [consumerRole] 166 | }); 167 | 168 | const groupDefaultRbacUser = new RedisRbacUser(this, "groupDefaultUser"+'RBAC', { 169 | redisUserName: 'default', 170 | redisUserId: 'groupdefaultuser', 171 | kmsKey: commonKmsKey 172 | }); 173 | 174 | // Create RBAC user group 175 | const mockAppUserGroup = new elasticache.CfnUserGroup(this, 'mockAppUserGroup', { 176 | engine: 'redis', 177 | userGroupId: 'mock-app-user-group', 178 | userIds: [producerRbacUser.getUserId(), groupDefaultRbacUser.getUserId(), consumerRbacUser.getUserId()] 179 | }) 180 | 181 | mockAppUserGroup.node.addDependency(producerRbacUser); 182 | mockAppUserGroup.node.addDependency(groupDefaultRbacUser); 183 | mockAppUserGroup.node.addDependency(consumerRbacUser); 184 | 185 | 186 | // ------------------------------------------------------------------------------------ 187 | // Step 4) Create an ElastiCache Redis Replication group and associate the RBAC user group 188 | // a) an ElastiCache subnet group will be created 189 | // b) the ElastiCache replication group will be associated with the RBAC user group 190 | // ------------------------------------------------------------------------------------ 191 | 192 | let isolatedSubnets: string[] = [] 193 | 194 | vpc.isolatedSubnets.forEach(function(value){ 195 | isolatedSubnets.push(value.subnetId) 196 | }); 197 | 198 | const ecSubnetGroup = new elasticache.CfnSubnetGroup(this, 'ElastiCacheSubnetGroup', { 199 | description: 'Elasticache Subnet Group', 200 | subnetIds: isolatedSubnets, 201 | cacheSubnetGroupName: 'RedisSubnetGroup' 202 | }); 203 | 204 | const elastiCacheKmsKey = new kms.Key(this, 'kmsForSecret', { 205 | alias: 'redisReplicationGroup/'+elasticacheReplicationGroupName, 206 | enableKeyRotation: true 207 | }); 208 | 209 | // elastiCacheKmsKey.grantEncrypt(producerRole); 210 | // elastiCacheKmsKey.grantDecrypt(consumerRole); 211 | 212 | const ecClusterReplicationGroup = new elasticache.CfnReplicationGroup(this, elasticacheReplicationGroupName, { 213 | replicationGroupDescription: 'RedisReplicationGroup-RBAC-Demo', 214 | atRestEncryptionEnabled: true, 215 | multiAzEnabled: true, 216 | cacheNodeType: 'cache.m6g.large', 217 | cacheSubnetGroupName: ecSubnetGroup.cacheSubnetGroupName, 218 | engine: "Redis", 219 | engineVersion: '6.x', 220 | numNodeGroups: 1, 221 | kmsKeyId: elastiCacheKmsKey.keyId, 222 | replicasPerNodeGroup: 1, 223 | securityGroupIds: [ecSecurityGroup.securityGroupId], 224 | transitEncryptionEnabled: true, 225 | userGroupIds: [mockAppUserGroup.userGroupId] 226 | }) 227 | 228 | ecClusterReplicationGroup.node.addDependency(ecSubnetGroup) 229 | ecClusterReplicationGroup.node.addDependency(mockAppUserGroup) 230 | 231 | // ------------------------------------------------------------------------------------ 232 | // Step 5) Create test functions 233 | // a) one producer 234 | // b) one consumer 235 | // c) one that cannot access Redis 236 | // ------------------------------------------------------------------------------------ 237 | const redisPyLayer = new lambda.LayerVersion(this, 'redispy_Layer', { 238 | code: lambda.Code.fromAsset(path.join(__dirname, 'lambda/lib/redis_module/redis_py.zip')), 239 | compatibleRuntimes: [lambda.Runtime.PYTHON_3_8, lambda.Runtime.PYTHON_3_7, lambda.Runtime.PYTHON_3_6], 240 | description: 'A layer that contains the redispy module', 241 | license: 'MIT License' 242 | }); 243 | 244 | 245 | const producerLambda = new lambda.Function(this, producerName+'Fn', { 246 | runtime: lambda.Runtime.PYTHON_3_7, 247 | handler: 'redis_connect.lambda_handler', 248 | code: lambda.Code.fromAsset(path.join(__dirname, 'lambda/mock_app.zip')), 249 | layers: [redisPyLayer], 250 | role: producerRole, 251 | vpc: vpc, 252 | vpcSubnets: {subnetType: ec2.SubnetType.PRIVATE_ISOLATED}, 253 | securityGroups: [lambdaSecurityGroup], 254 | environment: { 255 | redis_endpoint: ecClusterReplicationGroup.attrPrimaryEndPointAddress, 256 | redis_port: ecClusterReplicationGroup.attrPrimaryEndPointPort, 257 | secret_arn: producerRbacUser.getSecret().secretArn, 258 | } 259 | }); 260 | 261 | producerLambda.node.addDependency(redisPyLayer); 262 | producerLambda.node.addDependency(ecClusterReplicationGroup); 263 | producerLambda.node.addDependency(vpc); 264 | producerLambda.node.addDependency(producerRole); 265 | 266 | // Create a function that can only read from Redis 267 | const consumerFunction = new lambda.Function(this, consumerName+'Fn', { 268 | runtime: lambda.Runtime.PYTHON_3_7, 269 | handler: 'redis_connect.lambda_handler', 270 | code: lambda.Code.fromAsset(path.join(__dirname, 'lambda/mock_app.zip')), 271 | layers: [redisPyLayer], 272 | role: consumerRole, 273 | vpc: vpc, 274 | vpcSubnets: {subnetType: ec2.SubnetType.PRIVATE_ISOLATED}, 275 | securityGroups: [lambdaSecurityGroup], 276 | environment: { 277 | redis_endpoint: ecClusterReplicationGroup.attrPrimaryEndPointAddress, 278 | redis_port: ecClusterReplicationGroup.attrPrimaryEndPointPort, 279 | secret_arn: consumerRbacUser.getSecret().secretArn, 280 | } 281 | }); 282 | 283 | consumerFunction.node.addDependency(redisPyLayer); 284 | consumerFunction.node.addDependency(ecClusterReplicationGroup); 285 | consumerFunction.node.addDependency(vpc); 286 | consumerFunction.node.addDependency(consumerRole); 287 | 288 | // Create a function that cannot access Redis 289 | const noAccessFunction = new lambda.Function(this, noAccessName+'Fn', { 290 | runtime: lambda.Runtime.PYTHON_3_7, 291 | handler: 'redis_connect.lambda_handler', 292 | code: lambda.Code.fromAsset(path.join(__dirname, 'lambda/mock_app.zip')), 293 | layers: [redisPyLayer], 294 | role: consumerRole, 295 | vpc: vpc, 296 | vpcSubnets: {subnetType: ec2.SubnetType.PRIVATE_ISOLATED}, 297 | securityGroups: [lambdaSecurityGroup], 298 | environment: { 299 | redis_endpoint: ecClusterReplicationGroup.attrPrimaryEndPointAddress, 300 | redis_port: ecClusterReplicationGroup.attrPrimaryEndPointPort, 301 | secret_arn: producerRbacUser.getSecret().secretArn, 302 | } 303 | }); 304 | 305 | noAccessFunction.node.addDependency(redisPyLayer); 306 | noAccessFunction.node.addDependency(ecClusterReplicationGroup); 307 | noAccessFunction.node.addDependency(vpc); 308 | noAccessFunction.node.addDependency(noAccessRole); 309 | 310 | } 311 | 312 | } 313 | -------------------------------------------------------------------------------- /docs/architecture.md: -------------------------------------------------------------------------------- 1 | # AWS ElastiCache support for Redis Role Based Access Control (RBAC) 2 | 3 | With Amazon ElastiCache for Redis 6, you can control cluster access via a feature called Role-Based Access Control (RBAC). Through RBAC, you can define Access Control Lists (ACLs) that model access patterns – allowing you to better define who can access a Redis cluster and what commands and keys they can access. 4 | 5 | When configured for RBAC, ElastiCache Redis replication groups will authenticate RBAC users based on the username and password provided when connections are established, and Redis commands and key access are authorized by the access strings (defined in Redis ACL syntax) for each RBAC user. 6 | 7 | ![rbac user](img/rbac_user_example.png) 8 | 9 | Redis RBAC users and ACLs, however, are not linked to AWS Identity Access Management (IAM) roles, groups or users; the dissociation between AWS IAM and Redis RBAC means that there is no out-of-the-box way to grant IAM entities (roles, users or groups) read and write access to Redis. 10 | 11 | In this blog, we will present a solution that will allow you to associate IAM entities with ElastiCache RBAC users and ACLs. The overall solution will demonstrate how RBAC users can effectively be associated with IAM through the user of AWS Secrets Manager as a proxy for granting access to RBAC user credentials. 12 | 13 | * A set of Redis RBAC users will be defined; each with usernames, passwords and ACL access strings – this will define the commands and keys that a user has access to. 14 | 15 | * IAM entities (roles, users, groups) will be granted access to RBAC user credentials (username and password) stored in AWS Secrets Manager through secret policies and IAM policies. 16 | 17 | * Users, applications and services that have roles or users that can access RBAC user credentials from Secrets Manager can then use them to connect to ElasticacheRedis by assuming an RBAC user – which will also define which commands and keys they have access to. 18 | 19 | ## Design: Managing ElastiCache Redis access with RBAC, AWS SecretsManager and AWS IAM 20 | 21 | ### Storing Redis RBAC passwords in SecretsManager 22 | 23 | When RBAC users are created (either via AWS CLI, AWS API or AWS Cloudformation), they are specified with a plaintext password and a username. These usernames and passwords must be shared with the actors who will access the Redis replication group via RBAC users (human users or applications). 24 | 25 | The solution that we will present will leverage Secrets Manager to generate a password that will be used when the RBAC user is created meaning that no plaintext passwords exposed and must be retrieved through Secrets Manager. 26 | 27 | ### Managing access to RBAC passwords in SecretsManager with IAM 28 | 29 | Access to secrets in SecretsManager can be restricted to specific IAM entity – these entities can then retrieve the username and password by making the appropriate AWS API or CLI call. 30 | 31 | ### Tying it together: Managing access to Redis with RBAC, SecretsManager and IAM 32 | 33 | The combination of IAM policies of an IAM entity and the policies associated with the secret will determine which entities will be able to access the secret – and the RBAC username and password stored within; effectively linking an IAM entity with an RBAC user. 34 | 35 | ![rbac user actor flow](img/rbac_actor_flow.png) 36 | 37 | The above diagram demonstrates the flow of the solution. First, an actor with an IAM role that has permissions to the “Producer Credentials” secret reads the secret from AWS Secrets manager (1, 2); the actor then establishes a connection with the Producer credentials to an ElastiCache replication group that is configured with an RBAC user group that has the Producer RBAC User in it (3). Once authenticated (4), the user can perform commands and access keys (5), however the commands and keys that can be accessed are dictated by the access string on the Producer RBAC user. 38 | 39 | ## Implementation in AWS Cloud Development Kit (CDK) 40 | 41 | We present the solution to you in AWS Cloud Development Kit (CDK), which is a software development framework that defines infrastructure through object-oriented programming languages -- in our case, Typescript. 42 | 43 | The following will be deployed: 44 | * One VPC with isolated subnets, one AWS Secrets Manager VPC endpoint 45 | * One security group with an ingress rule that allows all traffic in via port 6379 46 | * Three ElasticaCache RBAC users: default, consumer, producer 47 | * Three secrets: default, producer, consumer 48 | * One ElastiCache RBAC user group 49 | * One ElastiCache subnet group 50 | * One ElastiCache replication group 51 | * Three IAM roles: consumer, producer, outsider 52 | * One Lambda layer which contains the redis-py Python module 53 | * Three Lambda functions: producerFn, consumerFn, outsiderFn 54 | 55 | ![architecture diagram](img/architecture_diagram_with_flow.png) 56 | 57 | A VPC is created for the purpose of hosting the ElastiCache replication group and the Lambda functions that will be used to demonstrate how to access ElastiCache. The code snippet defines the VPC with an isolated subnet, which in CDK terms, is a private subnet with no routing to the Internet. In order for resources in the isolated subnet to access Secrets Manager, a Secrets Manager VPC Interface Endpoint is added. 58 | 59 | 60 | ``` 61 | const vpc = new ec2.Vpc(this, "Vpc", { 62 | subnetConfiguration: [ 63 | { 64 | cidrMask: 24, 65 | name: 'Isolated', 66 | subnetType: ec2.SubnetType.PRIVATE_ISOLATED, 67 | } 68 | ] 69 | }); 70 | 71 | const secretsManagerEndpoint = vpc.addInterfaceEndpoint('SecretsManagerEndpoint', { 72 | service: ec2.InterfaceVpcEndpointAwsService.SECRETS_MANAGER, 73 | subnets: { 74 | subnetType: ec2.SubnetType.PRIVATE_ISOLATED 75 | } 76 | }); 77 | 78 | secretsManagerEndpoint.connections.allowDefaultPortFromAnyIpv4(); 79 | 80 | ``` 81 | 82 | To modularize the design of the solution, a RedisRbacUser class is also created. This class is composed of two CDK resources: a Secrets Manager Secret and an ElastiCache CfnUser; these resources are explicitly grouped together since the Secret stores the CfnUser password, and as will be shown later, read and decrypt permissions to the Secret will be granted to an IAM user. 83 | 84 | A note about unsafeUnwrap(); this method was added to the Secrets Manager library in CDK version 2 and is used in place of toString() to explicitly force the developer to understand the consequences of decoded secrets in code. For details, please see the documentation for [unsafeUnwrap()](https://docs.aws.amazon.com/cdk/api/v2/docs/aws-cdk-lib.SecretValue.html#unsafewbrunwrap) in the CDK API documentation. 85 | 86 | ``` 87 | export class RedisRbacUser extends cdk.Construct { 88 | ... 89 | 90 | constructor(scope: cdk.Construct, id: string, props: RedisRbacUserProps) { 91 | super(scope, id); 92 | 93 | ... 94 | 95 | this.rbacUserSecret = new secretsmanager.Secret(this, 'secret', { 96 | generateSecretString: { 97 | secretStringTemplate: JSON.stringify({ username: props.redisUserName }), 98 | generateStringKey: 'password', 99 | excludeCharacters: '@%*()_+=`~{}|[]\\:";\'?,./' 100 | }, 101 | }); 102 | 103 | const user = new elasticache.CfnUser(this, 'redisuser', { 104 | engine: 'redis', 105 | userName: props.redisUserName, 106 | accessString: props.accessString? props.accessString : "off +get ~keys*", 107 | userId: props.redisUserId, 108 | passwords: [this.rbacUserSecret.secretValueFromJson('password').unsafeUnwrap()] 109 | }) 110 | 111 | ... 112 | 113 | } 114 | 115 | } 116 | ``` 117 | 118 | The RedisRbacUser class is instantiated in the following code snippet, with an example of the Redis ACL syntax used in the accessString. 119 | 120 | ``` 121 | const producerRbacUser = new RedisRbacUser(this, producerName+'RBAC', { 122 | redisUserName: producerName, 123 | redisUserId: producerName, 124 | accessString: 'on ~* -@all +SET' 125 | }); 126 | ``` 127 | 128 | An IAM role is granted the ability to read the RedisRbacUser’s secret (the username and password). This association means that the IAM role can decrypt the username and password and use them to establish a connection with Redis as the producerRbacUser. 129 | 130 | ``` 131 | const producerRole = new iam.Role(this, producerName+'Role', { 132 | ... 133 | }); 134 | 135 | producerRbacUser.grantSecretRead(producerRole) 136 | ``` 137 | 138 | The function grantSecretRead in the RedisRbacUser class modifies the role that is passed into it to allow it to perform actions “secretsmanager:GetSecretValue” and “secretsmanager:DescribeSecret”. The same function also modifies the secret by adding a resource policy that allows the same actions and adds the provided role to the principal list – this prevents unlisted principals from attempting to access the secret once the stack is deployed. 139 | 140 | ``` 141 | public grantReadSecret(principal: iam.IPrincipal){ 142 | if (this.secretResourcePolicyStatement == null) { 143 | this.secretResourcePolicyStatement = new iam.PolicyStatement({ 144 | effect: iam.Effect.ALLOW, 145 | actions: ['secretsmanager:DescribeSecret', 'secretsmanager:GetSecretValue'], 146 | resources: [this.rbacUserSecret.secretArn], 147 | principals: [principal] 148 | }) 149 | 150 | this.rbacUserSecret.addToResourcePolicy(this.secretResourcePolicyStatement) 151 | 152 | } else { 153 | this.secretResourcePolicyStatement.addPrincipals(principal) 154 | } 155 | 156 | this.rbacUserSecret.grantRead(principal) 157 | } 158 | ``` 159 | 160 | A Lambda function then uses the IAM role created previously, so that it can decrypt the username and password Secret and access the ElastiCache for Redis replication group. 161 | 162 | ``` 163 | const producerLambda = new lambda.Function(this, producerName+'Fn', { 164 | ... 165 | role: producerRole, 166 | ... 167 | environment: { 168 | redis_endpoint: ecClusterReplicationGroup.attrPrimaryEndPointAddress, 169 | redis_port: ecClusterReplicationGroup.attrPrimaryEndPointPort, 170 | secret_arn: producerRbacUser.getSecret().secretArn, 171 | } 172 | }); 173 | ``` 174 | 175 | ## Deploying the solution 176 | 177 | The infrastructure for this solution is implemented in AWS Cloud Development Kit (CDK) in Typescript and can be cloned from this GitHub repository. 178 | 179 | You can setup your environment for CDK by following the AWS Cloud Development Kit Getting Started document here: https://docs.aws.amazon.com/cdk/latest/guide/getting_started.html#getting_started_prerequisites 180 | 181 | To deploy the solution, you’ll first want to build the lambda zip files that will be used in the Lambda functions; to do so, navigate to the root of the project on your machine and enter the following command in your terminal: 182 | 183 | ``` $ npm run-script zip ``` 184 | 185 | To deploy the solution to your account, run the following command from the root of the project: 186 | 187 | ``` $ cdk deploy ``` 188 | 189 | The command will attempt to deploy the solution in the default AWS profile defined in either your `~/.aws/config` file or your `~/.aws/credentials` file. You can also define a profile by specifying the `--profile profile_name` at the end of the command. 190 | 191 | ## Testing the solution 192 | 193 | Three Lambda functions were deployed as a part of the stack: a Producer, a Consumer and an Outsider function. 194 | 195 | ### Creating a Test JSON for each function 196 | 197 | To test each function, you’ll need to create a test event for each. To create a test object, click the ‘Test’ button in the Lambda console and use the default JSON object in the body – the test functions will not read the event contents. 198 | 199 | ![test json](img/test_trigger.png) 200 | 201 | You can trigger each test by clicking on the test button 202 | 203 | ![test button](img/test_button.png) 204 | 205 | ### Producer Function Reads and Writes to Redis 206 | 207 | This function demonstrates how an IAM role, attached to a Lambda function can be used to retrieve a username and password from Secrets Manager, then use these credentials to establish a connection to Redis and peform a write operation. 208 | 209 | The Producer function will write a key “time” with a value of the current time. 210 | 211 | ![producer log output](img/producer_log_output.png) 212 | 213 | The Producer function will be able to write to Redis, and that is because it’s IAM role allows it to get and decrypt the ‘Producer’ username and password in Secrets Manager and its RBAC user was created with an Redis ACL Access String that allows all SET commands to be performed 214 | 215 | ### Consumer Function Can Read but Cannot Write to Redis 216 | 217 | This function demonstrates the use case where you can allow a specific IAM role to access a Redis RBAC username and password from Secrets Manager and establish a connection with Redis, but the actions it can perform are restricted by an access string setting. 218 | 219 | The Consumer function will attempt to write a key “time” with a value of the current time; it will subsequently attempt to read back the key “time”. 220 | 221 | ![consumer log output](img/consumer_log_output.png) 222 | 223 | The Consumer function will not be able to write to Redis, but it will be able to read from it. Even though the function has an IAM role that permits it to get and decrypt the ‘Consumer’ username and password in Secrets Manager, the ‘Consumer’ RBAC user was created with a Redis ACL Access String value that only allows the ‘GET’ command. 224 | 225 | 226 | ### Outsider Function Cannot Read and Cannot Write to Redis 227 | 228 | This function demonstrates the use case where you can specify an IAM role that cannot access Redis because it cannot decrypt a username and password stored in Secrets Manager. 229 | 230 | The Outsider Lambda function will attempt to get and decrypt the ‘Producer’ username and password from Secrets Manager, then read and write to the Redis cluster. 231 | 232 | ![outsider log output](img/outsider_log_output.png) 233 | 234 | An exception is raised that indicates that it is not permitted to access the ‘Producer’ secret and that is because the IAM role attached to it does not have the permissions to decrypt the ‘Producer’ secret. 235 | 236 | ## Cost of Running the Solution 237 | 238 | The solution to associate an IAM entity with an ElastiCache RBAC user required the deployment of a sample ElastiCache cluster, storing secrets in AWS Secrets Manager and defining an RBAC user and an RBAC user group. 239 | 240 | * Secrets Manager: 241 | * $0.40 per secret per month, prorated for secrets stored less than a month 242 | * $0.05 per 10000 API calls 243 | * Assuming each of the three secrets are called 10 times for testing purposes in one day, the total cost would be (3 * $0.40 / 30) + (3 * 10 / 1000) * $0.05 = $0.04015 244 | 245 | * ElastiCache: 246 | * cache.m4.large node $0.156 per hour 247 | * Assuming that the node used for one day the total cost would be $3.744 248 | 249 | * Lambda Function: 250 | * $0.0000000021 per ms of execution time 251 | * Assuming that each lambda is called 10 times for testing purposes in one day and that the average execution time is 400ms, the total cost would be 3 * 400 * $0.000000021 = $0.00000252 252 | 253 | The total cost of the solution, for 24 hours, assuming that each of the three Lambda functions are called 10 times would be $3.78415252. 254 | 255 | ## Cleanup and Teardown 256 | 257 | To delete all resources from your account, including the VPC, you will need to call the following command from the project root folder: 258 | 259 | `$ cdk destroy` 260 | 261 | 262 | As in the cdk deploy command, the destroy command will attempt to execute on the default profile defined in ~/.aws/config or ~/.aws/credentials. You can specify another profile by providing --profile as a command line option. 263 | 264 | ## Conclusion 265 | 266 | While fine-grained access is now possible with the inclusion of Redis Role Based Access Control (RBAC) users, user groups and access strings in Amazon ElastiCache, there is no out-of-the box ability to associate RBAC users with IAM entities (roles, users and groups). This blog post presented a solution that restricted RBAC credentials (userame and password) access by storing them in AWS Secrets Manager and granting select IAM entities permissions to decrypt these credentials – effectively linking RBAC users with IAM roles. 267 | 268 | ### Additional benefits presented in this solution include: 269 | 270 | * RBAC passwords are not defined, stored or shared in plaintext when RBAC users are created 271 | * RBAC users and groups can be defined wholly in CDK (and by extension CloudFormation) and included as infrastructure-as-code 272 | * You can trace Redis access to IAM users since RBAC usernames and passwords are stored and accessed through AWS Secrets Manager and access to these credentials can be traced via CloudTrail 273 | 274 | 275 | ### Additional Resources 276 | 277 | * Amazon ElastiCache for Redis adds support for Redis 6 with managed Role-Based Access Control (RBAC) 278 | https://aws.amazon.com/about-aws/whats-new/2020/10/amazon-elasticache-redis-support-managed-role-based-access-control/ 279 | 280 | * Authenticating Users with Role-Based Access Control (RBAC) https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/Clusters.RBAC.html 281 | 282 | * Granting read access to one secret 283 | https://docs.aws.amazon.com/secretsmanager/latest/userguide/permissions_grant-get-secret-value-to-one-secret.html 284 | 285 | * Redis ACL 286 | https://redis.io/topics/acl 287 | -------------------------------------------------------------------------------- /docs/drawio/raw.drawio: -------------------------------------------------------------------------------- 1 | 7Vxbb9s4Fv41AWYeEoi62o++drroLIKm2Nl9MhiJtjmVRY9EJ3Z//ZIiqQtJJ05jOY6bIGjFQ4qkzjnfuYnKlTdabT/lcL38kyQovXKdZHvlja9ct+f77F9O2AkCiLxQUBY5TiStJtzhH0gSHUnd4AQVrYGUkJTidZsYkyxDMW3RYJ6Tx/awOUnbq67hAhmEuximJvUvnNClfK7Aqel/ILxYqpWBI3tWUA2WhGIJE/LYIHmTK2+UE0LF1Wo7QilnnuLL590PlPjI+ddkO5j/c5uSadC/FpNNX3JL9Qg5yuhxp3bF1A8w3Uh+/ed2JB+X7hQP1wRntJRDMGS/bJ2RcxWwnhFv3biBRtDbUZsAzBafo03Q21GbAPTpgbY+0DfYIBit1vSOtr7T2CD79YZkQ1OcoVGlsQ4jLnKYYCafEUlJzmgZyRj3hku6SlkLsMvHJabobg1jztVHhjZGm5OMSswAV7Ul4/msTOfW/Hq1XXB43sDHwr9Z5GSzLpf8zFBj7Z09rGN+O83Jd6S2dOV6rt/rAZ/1PKCcYoaSQYoXfApK+IxQtlI0p/x2tlmcLb6UrbHnyA025hsMhtGwx+gJLJYokbue4zTV+HCgCktV57tD2waApUp/QmSFaL5jQ2SvG0l0SvukcP1YYz1UiF42cB6GkgilfVlUU9cYYhcSRi+AVBgYmLrd3Kc45pja3GeIfuDr/eOrQPEmx3Q3qwfflWBTE+9FXhMcjD7pT71JeDxEVuu0ENkV/DzQhh+IfAN/gW/BH/DDjvDnmfDL8QOk6AN/vzL+gB9NhgML/sKpO+0dD3/VOm+CP883/Z8Vf9XAo+PPN/Bn4I2JLEsq3tj0pqFWhiSd8ue0YYYXaGGGa/LZ79nsnBd0xGczzDD4bAWy7i88d8pXNQDO+qaBH/n9Rt8Y52wiXIIyIzl/ch1Powh4YGqT27z80ZGhYPcF3qP0lhRYTn9PKCWrZ3EZs12hvK0xzxkdWKwFO+Z4y/dht0I5Ksgmj5GwQUPWtFkjZodyRIvZCmYsk8w7VMHAAy0VvK4y1YYORj1TBRXt6BrY614D/XHEOl+mgezHH/Z/GQ1EKSz49uLlWxvAkyofMEsXgxX8wfjDdxam3Fvf5+xqwa8mJZNGJZN0HWUcoG3xaU5fl/8KJwm/mUsE/4D3lVjbcSQPpeCGMoUSitChdHy396x0bN7J6yoIcA+wDSJyex1HqrqhlMJVszRn5VQ/bAdMfZNTAHgWR+50xqt+x3ZUxkaHOWo5+OwsZIktlE8ekIAY2Gs1SfoCQ1gp6vNY27UtWkNhvL6pL0qIx89vu3a7dnVxowiA8PLUZU1SHO9Eryjv86Ep3/oQxt8XZa5yoiwjBP5N1NeiPM+S0fVulPlrqlzQWUrnGCp3J/NvRv1U2/GGCuoSelrmuXgKlV9/453ja9ee5L0ufZxOZfooetRLIbepxfxG5lgoZCDKq3aawnWBa3ePtmuYqW3knCEFfkBfkXT4znkoVeDokVtgGjDXlrp25vHCN7Fge/KCd2/BGgnAbE7yWY4SXByuUBW4X1B0aimURZ9smUDY78o6mRXfU6jT2AlGILo8dUrh6j6Bs/kmk3n2ySoatlj8pDmlb9bUBn/dMcKdqPKwqz9lnefwJLKS3vmnkSHQSky+ayZHtmqy21nkYboKIQtG+yrLI+zyVgRxlymUyNMiQkvd77RSiYAhFYP3KFkgZZB4nY4sSAbTSU3Vwrh6zBdSRn+cp38jSnfSzHF266EdzOmAnxHiEmVesMDxtyXOVNcUp+lPCUfq1RMBjFRLtsoCPTWhNCicGU/KOmdOnLLgsTGoC7mZNbMPudkHRmcluPBEEbN5akHdoAU/F1lJLwOkDNHZAlL0CHddhj5+OymLTJMeWix6d4eWDqhBXrZliA61DOF5WYborS3DJVmADDbBf8LzBbo9cEH0xgbhgCozyhINq3sg3BbokZGr0v/j+fRmpdXCc0U7GOByhVueQdQi97W6XHWUR00hnlzeVYvTnEh7NWsoheCMMVGpF9VjvyKqNOsv/x5844VhiaTLTMs08bmeidj+SZMy8+DVZxnQ/GqysL7TPakszELSV0IhZa7Edb6UBTZ2MVUltssUivkyywcWwdhMbHeCOSCRuuw490BnqbzqmYS5quT7hmKqAuFaPuVLwIw933/lDWXjf7znxnN8RRhvm2PHu2brFuWYsah8y/jyg8LPits9VNzHlrY9VOlpX+voIc+eSIWJgLuuapi0aXuXCbRlPO3LOG1433vV8CAEmn6L/R43yDIT9NaZNmdw+9k89sb+hyueYJX0gkcCIy5F7otQ1SmHXqIT6ut5VWi+rAS278M6OxmnYpNz8kB7TNuRbZE6gPisMeq5Z+V7eqbE4hwxAKk3UZr0atns+yqmWd04XY0BeNHzYbLtIEhnRYae7T2SsGEJfmhxNfxnQ0rbVh2fuY4F2wZcERb3v7kBg7YjDJx2/TtvcMY6vHh0PYcrnO7EnZUR5AdEuMdeoSwlBrWazRzPYBe/5IaY4QTzN8hOhh7338fmJUWpNq29C5vJdw6C9bbq4/W9ayUz3ut6vFdxreEPau4KklDlmfiO4bcC5Q84RrM45TVAsROYZ+KCku8o+13NwSTemMbqe/S1yoerfkU3e8bMKumGeOVHP/O5+UQoxfPGjsRs1WoFReuSR+Ny6pcuCj0QgMDKRklhLlVZgcYg6274pE9xbi+f6l+22oegfk5QFBWnlBRf7kNUPyeqOc5wsTyhsMSCRxOXTr3EuBq46rtGdSrF9grTsxZAO/vytH+Gx1JOFFofmuf3zquso/bdkFjDo77XuNq1lTlPGlj3Tb7+Kkg49G1g7+glr9chwXyJ1gxZ3isUPMvXKyfOMc3XYu0A472y1g/ND9GOxVrWrP+umShh1n8dzpv8Hw== --------------------------------------------------------------------------------