Skip to content

Instantly share code, notes, and snippets.

@NeilMasters
Created August 14, 2026 13:31
Show Gist options
  • Select an option

  • Save NeilMasters/76d956ca6d7dd93b5c7485f090886421 to your computer and use it in GitHub Desktop.

Select an option

Save NeilMasters/76d956ca6d7dd93b5c7485f090886421 to your computer and use it in GitHub Desktop.
Create the differences between old and current version of aws secrets.
#!/usr/bin/env bash
set -euo pipefail
###############################################################################
#
# A simple shell script that will compare an aws secret' current and previous
# version and then print a) what has been added, b) what has been removed and
# c) what has changed.
#
# Notes:
# This is specifically for compare json formatted secrets. It will not work
# for simple strings.
#
# Usage:
# ./diff-secrets.sh aws-secret-name
#
###############################################################################
if [[ $# -ne 1 ]]; then
echo "Usage: $0 <secret-id>" >&2
exit 1
fi
SECRET_ID="$1"
CUR=$(aws secretsmanager get-secret-value --secret-id "$SECRET_ID" --version-stage AWSCURRENT --query SecretString --output text)
PREV=$(aws secretsmanager get-secret-value --secret-id "$SECRET_ID" --version-stage AWSPREVIOUS --query SecretString --output text)
jq -n --argjson cur "$CUR" --argjson prev "$PREV" '
(($cur | keys_unsorted) + ($prev | keys_unsorted) | unique) as $keys
| [ $keys[] as $k
| if ($prev | has($k) | not) then {key: $k, status: "added", value: $cur[$k]}
elif ($cur | has($k) | not) then {key: $k, status: "removed", value: $prev[$k]}
elif ($cur[$k] != $prev[$k]) then {key: $k, status: "changed", from: $prev[$k], to: $cur[$k]}
else empty
end
]
'
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment