Snippets – Github Actions Secret Recovery

Written by

in

Here’s a quick workflow to recover any secrets from GitHub actions; it will save them to AWS Secrets Manager. Remember to remove the workflow and your AWS credentials once you’re complete. The AWS Credentials can be scoped to just SecretsManager create etc.

name: Move Config

on:
  workflow_dispatch:
    inputs:
      environment:       
        description: 'Target environment'
        type: environment   # dropdown of repo environments
        required: true

permissions:
  contents: read
  
jobs:
  move-config:
    runs-on: ubuntu-latest
    environment: ${{ inputs.environment }}
    steps:
      - name: Checkout
        uses: actions/checkout@v4
    
      - uses: aws-actions/configure-aws-credentials@v5
        with:
          aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
          aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}    
          aws-region: eu-west-1

      - env:
          VAL: ${{ secrets.<NAME_OF_GITHUB_SECRET>}}
        run: |
          jq -n --arg t "$VAL" '{value: $t}' > out.json          
          aws secretsmanager create-secret --name <name-in-secrtsmngr> --secret-string file://./out.json
          rm out.json