Maintain a JFrog access token in AWS Secrets Manager with automatic rotation, so AWS ECS (and other consumers) can pull private registry images using short-lived tokens - without storing long-lived JFrog credentials in the rotation function. Rotation is controlled by the Lambda execution IAM role and JFrog AWS IAM role tagging.
An AWS Lambda function implements the Secrets
Manager rotation contract. On each rotation, it exchanges the Lambda IAM
credentials for a JFrog access token (SigV4 to JFrog AWS token endpoint), stores
the result as AWSPENDING, tests it, then promotes it to AWSCURRENT.
The function source code is in
secret-rotator/lambda_function.py. It is
deployed as a Python zip on the managed python3.14 runtime (AWS SDK
dependencies come from the runtime).
- createSecret - Sign a request with the Lambda IAM role, exchange for a
JFrog access token, store JSON
{"username","password"}asAWSPENDING - setSecret - Skipped (not needed for JFrog)
- testSecret - Call JFrog access readiness with the pending token
- finishSecret - Promote
AWSPENDINGtoAWSCURRENT
| Variable | Description | Required | Example |
|---|---|---|---|
JFROG_HOST |
JFrog Artifactory hostname | Yes | mycompany.jfrog.io |
SECRET_TTL |
Token expiration time in seconds | Yes | 21600 |
This Lambda uses regional STS authentication based on the Lambda region.
┌─────────────┐ ┌─────────────┐ ┌─────────────┐
│ createSecret│ -> │ testSecret │ -> │finishSecret │
└─────────────┘ └─────────────┘ └─────────────┘
sequenceDiagram
participant SM as Secrets Manager
participant L as Lambda
participant JF as JFrog Access
participant ECS as ECS / consumers
SM->>L: createSecret
L->>L: IAM credentials (SigV4)
L->>JF: POST /access/api/v1/aws/token
JF-->>L: access_token + username
L->>SM: PutSecretValue AWSPENDING
SM->>L: testSecret
L->>JF: readiness check
SM->>L: finishSecret
L->>SM: promote AWSPENDING to AWSCURRENT
ECS->>SM: GetSecretValue AWSCURRENT
Choose one deployment path:
- Manual setup (AWS CLI & REST API) - step-by-step
awscommands and JFrog IAM role tagging via curl. The first step builds the deployment zip withscripts/build-lambda-zip.sh. - Terraform setup - Infrastructure-as-Code via
terraform-example/; Terraform packagessecret-rotator/lambda_function.pyinto a zip via thearchiveprovider. Optionally tags a JFrog user with the Lambda IAM role (assign_jfrog_iam_role, defaulttrue).
Both paths provision the rotation pipeline and deploy the Lambda as a Python zip package.
- The Lambda uses AWS IAM roles for authentication (no hardcoded credentials)
- Tokens are stored in AWS Secrets Manager
- API calls are signed with AWS SigV4
- Configure
SECRET_TTLand the secret rotation schedule so the token outlives the rotation interval
Apache-2.0