VOOZH about

URL: https://www.nuget.org/packages/SecureRequest.AwsSecretsManager

⇱ NuGet Gallery | SecureRequest.AwsSecretsManager 1.0.0




SecureRequest.AwsSecretsManager 1.0.0

dotnet add package SecureRequest.AwsSecretsManager --version 1.0.0
 
 
NuGet\Install-Package SecureRequest.AwsSecretsManager -Version 1.0.0
 
 
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="SecureRequest.AwsSecretsManager" Version="1.0.0" />
 
 
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="SecureRequest.AwsSecretsManager" Version="1.0.0" />
 
Directory.Packages.props
<PackageReference Include="SecureRequest.AwsSecretsManager" />
 
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add SecureRequest.AwsSecretsManager --version 1.0.0
 
 
The NuGet Team does not provide support for this client. Please contact its maintainers for support.
#r "nuget: SecureRequest.AwsSecretsManager, 1.0.0"
 
 
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package SecureRequest.AwsSecretsManager@1.0.0
 
 
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=SecureRequest.AwsSecretsManager&version=1.0.0
 
Install as a Cake Addin
#tool nuget:?package=SecureRequest.AwsSecretsManager&version=1.0.0
 
Install as a Cake Tool
The NuGet Team does not provide support for this client. Please contact its maintainers for support.

SecureRequest.AwsSecretsManager

AWS Secrets Manager provider for the SecureRequest NuGet package.

Stores the RSA private key inside AWS Secrets Manager instead of Redis/IDistributedCache, protected by IAM access control, CloudTrail audit logging, and KMS encryption at rest.


Installation

dotnet add package SecureRequest
dotnet add package SecureRequest.AwsSecretsManager

Usage

Chain .WithAwsSecretsManager() onto AddSecureRequest():

builder.Services
 .AddSecureRequest(builder.Configuration)
 .WithAwsSecretsManager(); // uses default AWS credential chain (IAM role, env vars, ~/.aws)

The AWS SDK default credential chain is used automatically — picks up IAM roles (EC2/ECS/Lambda/EKS), environment variables (AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY), and ~/.aws/credentials in development.


Custom secret ID and region

builder.Services
 .AddSecureRequest(builder.Configuration)
 .WithAwsSecretsManager(
 secretId : "myapp/prod/rsa-key",
 region : RegionEndpoint.EUWest1);

Bring your own client (already in DI)

// Register with custom credentials
builder.Services.AddSingleton<IAmazonSecretsManager>(
 new AmazonSecretsManagerClient(new StoredProfileAWSCredentials("my-profile")));

builder.Services
 .AddSecureRequest(builder.Configuration)
 .WithAwsSecretsManager(
 clientFactory: sp => sp.GetRequiredService<IAmazonSecretsManager>());

Required IAM permissions

The IAM role or user running the application needs the following policy:

{
 "Effect": "Allow",
 "Action": [
 "secretsmanager:GetSecretValue",
 "secretsmanager:CreateSecret",
 "secretsmanager:PutSecretValue"
 ],
 "Resource": "arn:aws:secretsmanager:REGION:ACCOUNT:secret:secure-request/rsa-private-key*"
}

On first startup the provider creates the secret (CreateSecret). On every subsequent startup it reads it back (GetSecretValue). On key rotation it updates the value (PutSecretValue).


appsettings.json

No changes needed — SecureRequest options are still bound from the same section:

"SecureRequest": {
 "Enabled": true,
 "EnableBodyEncryption": true,
 "EnableHmacSigning": true,
 "TimestampToleranceSeconds": 300,
 "NonceCacheTtlSeconds": 700,
 "SecuredMethods": ["POST", "PUT", "PATCH"],
 "ExcludedPaths": []
}

Note: IDistributedCache is still required for nonce anti-replay storage. Only the RSA private key moves to Secrets Manager — nonces remain in Redis/in-memory cache.


Comparison

Default (Redis) AwsSecretsManagerKeyStorageProvider
Key stored in Redis (plain Base64) AWS Secrets Manager (KMS-encrypted)
Access control Redis connection string IAM roles and policies
Audit trail None AWS CloudTrail
Encryption at rest Depends on Redis config AES-256 via AWS KMS (automatic)
Compliance Not sufficient for PCI-DSS / HIPAA Satisfies requirements

License

MIT

Product Versions Compatible and additional computed target framework versions.
.NET net8.0 net8.0 is compatible.  net8.0-android net8.0-android was computed.  net8.0-browser net8.0-browser was computed.  net8.0-ios net8.0-ios was computed.  net8.0-maccatalyst net8.0-maccatalyst was computed.  net8.0-macos net8.0-macos was computed.  net8.0-tvos net8.0-tvos was computed.  net8.0-windows net8.0-windows was computed.  net9.0 net9.0 was computed.  net9.0-android net9.0-android was computed.  net9.0-browser net9.0-browser was computed.  net9.0-ios net9.0-ios was computed.  net9.0-maccatalyst net9.0-maccatalyst was computed.  net9.0-macos net9.0-macos was computed.  net9.0-tvos net9.0-tvos was computed.  net9.0-windows net9.0-windows was computed.  net10.0 net10.0 was computed.  net10.0-android net10.0-android was computed.  net10.0-browser net10.0-browser was computed.  net10.0-ios net10.0-ios was computed.  net10.0-maccatalyst net10.0-maccatalyst was computed.  net10.0-macos net10.0-macos was computed.  net10.0-tvos net10.0-tvos was computed.  net10.0-windows net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0 21,640 6/12/2026