|
| 1 | +#!/bin/bash |
| 2 | +# Tutorial: Create a KMS key and encrypt data |
| 3 | +# Source: https://docs.aws.amazon.com/kms/latest/developerguide/getting-started.html |
| 4 | + |
| 5 | +WORK_DIR=$(mktemp -d) |
| 6 | +LOG_FILE="$WORK_DIR/kms-$(date +%Y%m%d-%H%M%S).log" |
| 7 | +exec > >(tee -a "$LOG_FILE") 2>&1 |
| 8 | + |
| 9 | +REGION=${AWS_DEFAULT_REGION:-${AWS_REGION:-$(aws configure get region 2>/dev/null)}} |
| 10 | +if [ -z "$REGION" ]; then |
| 11 | + echo "ERROR: No AWS region configured. Set one with: export AWS_DEFAULT_REGION=us-east-1" |
| 12 | + exit 1 |
| 13 | +fi |
| 14 | +export AWS_DEFAULT_REGION="$REGION" |
| 15 | +echo "Region: $REGION" |
| 16 | + |
| 17 | +RANDOM_ID=$(openssl rand -hex 4) |
| 18 | +ALIAS_NAME="alias/tutorial-key-${RANDOM_ID}" |
| 19 | + |
| 20 | +handle_error() { echo "ERROR on line $1"; trap - ERR; cleanup; exit 1; } |
| 21 | +trap 'handle_error $LINENO' ERR |
| 22 | + |
| 23 | +cleanup() { |
| 24 | + echo "" |
| 25 | + echo "Cleaning up resources..." |
| 26 | + if [ -n "$KEY_ID" ]; then |
| 27 | + aws kms schedule-key-deletion --key-id "$KEY_ID" --pending-window-in-days 7 > /dev/null 2>&1 && \ |
| 28 | + echo " Scheduled key $KEY_ID for deletion in 7 days" |
| 29 | + fi |
| 30 | + aws kms delete-alias --alias-name "$ALIAS_NAME" 2>/dev/null && echo " Deleted alias $ALIAS_NAME" |
| 31 | + rm -rf "$WORK_DIR" |
| 32 | + echo "Cleanup complete." |
| 33 | +} |
| 34 | + |
| 35 | +# Step 1: Create a customer managed key |
| 36 | +echo "Step 1: Creating a customer managed KMS key" |
| 37 | +KEY_ID=$(aws kms create-key --description "Tutorial key ${RANDOM_ID}" \ |
| 38 | + --query 'KeyMetadata.KeyId' --output text) |
| 39 | +echo " Key ID: $KEY_ID" |
| 40 | + |
| 41 | +# Step 2: Create an alias |
| 42 | +echo "Step 2: Creating alias: $ALIAS_NAME" |
| 43 | +aws kms create-alias --alias-name "$ALIAS_NAME" --target-key-id "$KEY_ID" |
| 44 | +echo " Alias created" |
| 45 | + |
| 46 | +# Step 3: Describe the key |
| 47 | +echo "Step 3: Describing the key" |
| 48 | +aws kms describe-key --key-id "$KEY_ID" \ |
| 49 | + --query 'KeyMetadata.{KeyId:KeyId,State:KeyState,Created:CreationDate,Description:Description}' --output table |
| 50 | + |
| 51 | +# Step 4: Encrypt data |
| 52 | +echo "Step 4: Encrypting data" |
| 53 | +echo "Hello from the KMS tutorial" > "$WORK_DIR/plaintext.txt" |
| 54 | +aws kms encrypt --key-id "$KEY_ID" \ |
| 55 | + --plaintext "fileb://$WORK_DIR/plaintext.txt" \ |
| 56 | + --output text --query 'CiphertextBlob' > "$WORK_DIR/ciphertext.b64" |
| 57 | +echo " Plaintext: $(cat "$WORK_DIR/plaintext.txt")" |
| 58 | +echo " Ciphertext (base64, first 40 chars): $(head -c 40 "$WORK_DIR/ciphertext.b64")..." |
| 59 | + |
| 60 | +# Step 5: Decrypt data |
| 61 | +echo "Step 5: Decrypting data" |
| 62 | +cat "$WORK_DIR/ciphertext.b64" | base64 --decode > "$WORK_DIR/ciphertext.bin" |
| 63 | +aws kms decrypt --ciphertext-blob "fileb://$WORK_DIR/ciphertext.bin" \ |
| 64 | + --output text --query 'Plaintext' | base64 --decode > "$WORK_DIR/decrypted.txt" |
| 65 | +echo " Decrypted: $(cat "$WORK_DIR/decrypted.txt")" |
| 66 | + |
| 67 | +# Step 6: Generate a data key |
| 68 | +echo "Step 6: Generating a data key" |
| 69 | +aws kms generate-data-key --key-id "$KEY_ID" --key-spec AES_256 \ |
| 70 | + --query '{KeyId:KeyId}' --output table |
| 71 | +echo " Data key generated (plaintext + encrypted copy returned)" |
| 72 | + |
| 73 | +# Step 7: List keys |
| 74 | +echo "Step 7: Listing KMS keys (first 5)" |
| 75 | +aws kms list-aliases --query 'Aliases[?starts_with(AliasName, `alias/tutorial`)].{Alias:AliasName,KeyId:TargetKeyId}' --output table |
| 76 | + |
| 77 | +echo "" |
| 78 | +echo "Tutorial complete." |
| 79 | +echo "Do you want to clean up all resources? (y/n): " |
| 80 | +read -r CHOICE |
| 81 | +if [[ "$CHOICE" =~ ^[Yy]$ ]]; then |
| 82 | + cleanup |
| 83 | +else |
| 84 | + echo "Resources left running. The key will incur $1/month until deleted." |
| 85 | + echo "Manual cleanup:" |
| 86 | + echo " aws kms schedule-key-deletion --key-id $KEY_ID --pending-window-in-days 7" |
| 87 | + echo " aws kms delete-alias --alias-name $ALIAS_NAME" |
| 88 | +fi |
0 commit comments