Processing secrets that have become publicly available
Yandex Cloud automatically searches for publicly available secrets. If a secret is exposed publicly, the organization owner or user indicated as the Identity and Access Management notification recipient in the organization settings will get an email from the Yandex Cloud support address. To keep your data and infrastructure secure, carefully monitor how your secrets are used.
If your secrets are compromised:
- Revoke and reissue the secrets.
- Check for any unauthorized actions.
- Delete unauthorized resources.
- Contact support.
- Follow our recommendations on building a secure infrastructure.
Revoke and reissue the secrets
IAM token
To prevent an intruder from using your token:
-
Revoke the compromised IAM token.
-
Create a new IAM token.
OAuth token
OAuth token authentication is deprecated
This authentication method is no longer supported. Consider using IAM tokens or API keys.
You can revoke an OAuth token. In this case, the IAM tokens obtained using the OAuth token will remain valid. Therefore, make sure to revoke all such IAM tokens as well.
To prevent an intruder from using your token:
- Revoke the OAuth token
. Do it by revoking access from the Yandex Cloud application. - Revoke all IAM tokens obtained using the compromised OAuth token.
- Get a new OAuth token
.
Authorized key
If you need to prevent threats posed by a compromised key as quickly as possible, delete the service account.
If you prioritize keeping the process that uses the service account running, reissue the authorized keys:
- Create a new authorized key for the service account.
- Provide the new authorized key to the services and users that need it.
- Get an IAM token for the new authorized key.
- Delete the old authorized key.
Once you delete the authorized key, the respective IAM token becomes invalid. That is enough to prevent any threat from the compromised key.
JWT
Follow the steps described in the Authorized key section.
Static key
- Create a new static key for the service account.
- Provide the new static key to the services and users that need it.
- Delete the old static key.
API key
- Create a new API key for the service account.
- Provide the new API key to the services and users that need it.
- Delete the old API key.
SmartCaptcha server key
Create a new CAPTCHA and, on the website page, replace the old CAPTCHA, whose server key was compromised, with the new one.
Cookie
Disable cookies:
- Change
your Yandex ID password. - Log in to Yandex ID
with your new password.
Check for any unauthorized actions
Analyze access to your Yandex Cloud resources:
- Analyze log records in Cloud Logging.
- Search for events in a bucket or log group in Audit Trails.
- Make sure that all events, including those related to secret leaks, match your expectations.
Tip
You can configure exporting audit logs to a SIEM system.
Delete unauthorized resources
- Check Yandex Cloud for any resources that you did not create, such as VMs, data storages, databases, functions, API gateways, and so on.
- Delete unauthorized resources.
Contact support
Report the incident to the support
You can learn more about the support terms here.
Follow our recommendations on building a secure infrastructure
- Make sure to separate secrets from the source code. This will prevent adding them to public repositories, such as GitHub, along with the code and making them vulnerable.
- Manage secrets in your cloud.
- Collect, monitor, and analyze audit logs.