Skip to content

sec(iac): secretsmanager:ListSecrets in SecretsManager block is non-functional (must use Resource="*") #1267

Description

@cristim

Finding

The SecretsManager block in terraform/environments/aws/ci-cd-permissions/policy_data.tf includes secretsmanager:ListSecrets scoped to Resource = "arn:aws:secretsmanager:*:*:secret:cudly-*":

{
  Sid    = "SecretsManager"
  Effect = "Allow"
  Action = [
    ...
    "secretsmanager:ListSecrets",
    ...
  ]
  Resource = "arn:aws:secretsmanager:*:*:secret:cudly-*"
}

Per the AWS Service Authorization Reference for Secrets Manager, secretsmanager:ListSecrets does NOT support resource-level permissions — it only works with Resource = "*". When granted on a specific ARN, IAM will never match the request (which is an account-level call with no resource target), so the permission is effectively a no-op.

Impact

  • No security regression: the permission doesn't accidentally grant anything
  • No functional regression from PR sec(iac): scope SecretsManagerDescribe to specific actions (closes #430) #817 removing the duplicate wildcard SecretsManagerDescribe block: that block was already the only real grant of ListSecrets
  • However, the ListSecrets entry in the SecretsManager block is dead code that misleads readers into thinking the deploy role can enumerate secrets

Resolution options

  1. Remove secretsmanager:ListSecrets from the SecretsManager block — if Terraform deploy never actually calls ListSecrets (it uses DescribeSecret for all known-ARN lookups). This would be the cleanest outcome.
  2. Add a separate SecretsManagerList block with Resource = "*" — if ListSecrets is genuinely needed at deploy time (e.g. for terraform import workflows). This would restore the functional permission that PR sec(iac): scope SecretsManagerDescribe to specific actions (closes #430) #817 removed.

Discovered during adversarial review of PR #817.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions