Skip to content

KMS lookups give values $VAL wrapped as "b'$VAL'" when using python 3 #755

Description

@hauntingEcho

While attempting to encrypt a password 'hello!' per the directions here:

  1. the command given for encryption fails entirely
  2. after getting encryption working, Stacker populated incorrect values

using the suggested encryption command aws kms encrypt --key-id alias/DbConnectionKey --plaintext 'hello!' --output text --query CiphertextBlob results in:

Invalid base64: "hello!"

From there, I attempted to use aws kms encrypt --key-id alias/DbConnectionKey --plaintext fileb://<(echo -n 'hello!') --output text --query CiphertextBlob and used the result to create a secret via Stacker. In this secret, I see:

image

Does this need a different configuration than the one from the docs, or is there another way I should be doing this? I'm currently using Stacker 1.7.0 on python 3.5.3. I've also tried dropping the '!' off the end and received the same behavior with just "hello".

Activity

  1. changed the title [-]KMS lookups do not work if password is not valid base64[/-] [+]KMS lookups give values $VAL wrapped as "b'$VAL'"[/+] on Mar 31, 2020
  2. changed the title [-]KMS lookups give values $VAL wrapped as "b'$VAL'"[/-] [+]KMS lookups give values $VAL wrapped as "b'$VAL'" when using python 3[/+] on Mar 31, 2020
  3. hauntingEcho commented on Mar 31, 2020

    @hauntingEcho
    ContributorAuthor

    after uninstalling via pip3 and reinstalling via pip2, the issue only affects Python 3. For what it's worth, aws --version gives me aws-cli/2.0.0 Python/3.7.3 Linux/4.4.0-17763-Microsoft botocore/2.0.0dev4

  4. hauntingEcho commented on Sep 4, 2020

    @hauntingEcho
    Author
  5. baryal1299 commented on Sep 8, 2020

    @baryal1299

    This has been resolved with 1.7.1

    Still seeing the same issue, is this fixed for python 3?

    $ aws --version aws-cli/1.16.199 Python/3.6.7 Darwin/18.7.0 botocore/1.15.39
    $ stacker --version stacker 1.7.1

    I went ahead and opened a pull request: #762

  6. hauntingEcho commented on Sep 8, 2020

    @hauntingEcho
    ContributorAuthor

    you're right, I hadn't cleaned out my python2 installation and am seeing this issue again

  7. bmcoelho commented on Oct 29, 2020

    @bmcoelho
    Contributor

    Hi guys,

    Any chance to fix this in the next release? All the secrets are now showing as b'secret'

    Thanks

  8. hauntingEcho commented on Nov 5, 2020

    @hauntingEcho
    ContributorAuthor

    It looks like this should be fixed by your PR #765 , pending release ( #766 )

  9. phobologic commented on Nov 5, 2020

    @phobologic
    Member

    I'll go ahead and get a dot release out by this weekend.

  10. phobologic commented on Nov 10, 2020

    @phobologic
    Member
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions