Sample code for 30+ languages & platforms
Zig

AWS Setup Bootstrap Secret in Local Manager

See more Secrets Examples

Accessing a cloud-based secrets manager requires authentication credentials, which cannot be stored in the manager itself. Instead, they must be securely stored locally.

One solution is to store the authentication credentials as a secret in the Windows Credentials Manager or Apple Keychain. These credentials serve as the "bootstrap secret" for authenticating with the cloud-based secrets manager.

This example demonstrates how to setup a bootstrap secret for the AWS Secrets Manager.

Note: This example requires Chilkat v10.1.0 or later.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    // This example requires the Chilkat API to have been previously unlocked.
    // See Global Unlock Sample for sample code.

    const bootstrap = try chilkat.Secrets.init();
    defer bootstrap.deinit();

    // On Windows, this is the Windows Credentials Manager
    // On MacOS/iOS, it is the Apple Keychain
    bootstrap.setLocation("local_manager");

    // Specify the name of the bootstrap secret.
    // service and username are required.
    // appName and domain are optional.
    // Note: The values are arbitrary and can be anything you want.
    const json = try chilkat.JsonObject.init();
    defer json.deinit();
    json.updateString("appName", "AWS") catch {};
    json.updateString("service", "Example") catch {};
    json.updateString("username", "Joe") catch {};

    // The bootstrap secret for the AWS Secrets Manager will contain
    // the AWS region, access key, and secret key, like this:
    const json_secret = try chilkat.JsonObject.init();
    defer json_secret.deinit();
    // Modify if necessary to use your region..
    json_secret.updateString("awsRegion", "us-east-1") catch {};
    json_secret.updateString("awsAccessKey", "YOUR_ACCESS_KEY") catch {};
    json_secret.updateString("awsSecretKey", "YOUR_SECRET_KEY") catch {};

    // Create or update the bootstrap secret.
    bootstrap.updateSecretJson(json, json_secret) catch {
        std.debug.print("{s}\n", .{try bootstrap.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("The AWS bootstrap secret has been stored.\n", .{});
}