Skip to content

Instantly share code, notes, and snippets.

@nmagee
Created October 2, 2018 17:17
Show Gist options
  • Select an option

  • Save nmagee/ee613b1b0dadabe38adb0152a4ab73e3 to your computer and use it in GitHub Desktop.

Select an option

Save nmagee/ee613b1b0dadabe38adb0152a4ab73e3 to your computer and use it in GitHub Desktop.
#!/usr/local/bin/python3
# A dumb/simple script to retrieve the value of a SecretsManager secret
import boto3
import base64
from botocore.exceptions import ClientError
def get_secret():
secret_name = "<KEY_NAME_GOES_HERE>"
region_name = "us-east-1"
# Create a Secrets Manager client
session = boto3.session.Session()
client = session.client(
service_name='secretsmanager',
region_name=region_name
)
try:
get_secret_value_response = client.get_secret_value(
SecretId=secret_name
)
except ClientError as e:
if e.response['Error']['Code'] == 'DecryptionFailureException':
# Secrets Manager can't decrypt the protected secret text using the provided KMS key.
raise e
elif e.response['Error']['Code'] == 'InternalServiceErrorException':
# An error occurred on the server side.
raise e
elif e.response['Error']['Code'] == 'InvalidParameterException':
# You provided an invalid value for a parameter.
raise e
elif e.response['Error']['Code'] == 'InvalidRequestException':
# You provided a parameter value that is not valid for the current state of the resource.
raise e
elif e.response['Error']['Code'] == 'ResourceNotFoundException':
# We can't find the resource that you asked for.
raise e
else:
# Depending on whether the secret is a string or binary, one of these fields will be populated.
if 'SecretString' in get_secret_value_response:
secret = get_secret_value_response['SecretString']
else:
decoded_binary_secret = base64.b64decode(get_secret_value_response['SecretBinary'])
print(secret)
get_secret()
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment