Created
July 22, 2021 07:39
-
-
Save ryan-blunden/6c608bd14097e9bf692c5a7f2515bfcf to your computer and use it in GitHub Desktop.
The secrets_getsecretvalue.js file demonstrates how to retrieve a secret from AWS Secrets Manager.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
/** | |
* From https://docs.aws.amazon.com/code-samples/latest/catalog/javascript-secrets-secrets_getsecretvalue.js.html | |
* | |
* Copyright 2010-2019 Amazon.com, Inc. or its affiliates. All Rights Reserved. | |
* | |
* This file is licensed under the Apache License, Version 2.0 (the "License"). | |
* You may not use this file except in compliance with the License. A copy of | |
* the License is located at | |
* | |
* http://aws.amazon.com/apache2.0/ | |
* | |
* This file is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR | |
* CONDITIONS OF ANY KIND, either express or implied. See the License for the | |
* specific language governing permissions and limitations under the License. | |
*/ | |
// ABOUT THIS NODE.JS SAMPLE: This sample is part of the AWS Secrets Manager. | |
// In this sample we only handle the specific exceptions for the 'GetSecretValue' API. | |
// If you need more information about configurations or implementing the sample code, visit the AWS docs: | |
// https://aws.amazon.com/developers/getting-started/nodejs/ | |
// Load the AWS SDK | |
var AWS = require('aws-sdk'), | |
region = "<<{{MyRegionName}}>>", | |
secretName = "<<{{MySecretName}}>>", | |
secret, | |
decodedBinarySecret; | |
// Create a Secrets Manager client | |
var client = new AWS.SecretsManager({ | |
region: region | |
}); | |
// In this sample we only handle the specific exceptions for the 'GetSecretValue' API. | |
// See https://docs.aws.amazon.com/secretsmanager/latest/apireference/API_GetSecretValue.html | |
// We rethrow the exception by default. | |
client.getSecretValue({SecretId: secretName}, function(err, data) { | |
if (err) { | |
if (err.code === 'DecryptionFailureException') | |
// Secrets Manager can't decrypt the protected secret text using the provided KMS key. | |
// Deal with the exception here, and/or rethrow at your discretion. | |
throw err; | |
else if (err.code === 'InternalServiceErrorException') | |
// An error occurred on the server side. | |
// Deal with the exception here, and/or rethrow at your discretion. | |
throw err; | |
else if (err.code === 'InvalidParameterException') | |
// You provided an invalid value for a parameter. | |
// Deal with the exception here, and/or rethrow at your discretion. | |
throw err; | |
else if (err.code === 'InvalidRequestException') | |
// You provided a parameter value that is not valid for the current state of the resource. | |
// Deal with the exception here, and/or rethrow at your discretion. | |
throw err; | |
else if (err.code === 'ResourceNotFoundException') | |
// We can't find the resource that you asked for. | |
// Deal with the exception here, and/or rethrow at your discretion. | |
throw err; | |
} | |
else { | |
// Decrypts secret using the associated KMS CMK. | |
// Depending on whether the secret is a string or binary, one of these fields will be populated. | |
if ('SecretString' in data) { | |
secret = data.SecretString; | |
} else { | |
let buff = new Buffer(data.SecretBinary, 'base64'); | |
decodedBinarySecret = buff.toString('ascii'); | |
} | |
} | |
// Your code goes here. | |
}); |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment