惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
P
Proofpoint News Feed
The Cloudflare Blog
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
美团技术团队
Spread Privacy
Spread Privacy
Latest news
Latest news
Cisco Talos Blog
Cisco Talos Blog
T
Threatpost
Project Zero
Project Zero
博客园 - 司徒正美
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Simon Willison's Weblog
Simon Willison's Weblog
Apple Machine Learning Research
Apple Machine Learning Research
腾讯CDC
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
F
Fortinet All Blogs
Security Latest
Security Latest
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
Cyberwarzone
Cyberwarzone
The Hacker News
The Hacker News
Scott Helme
Scott Helme
T
Tor Project blog
Engineering at Meta
Engineering at Meta
H
Help Net Security
Recorded Future
Recorded Future
Microsoft Azure Blog
Microsoft Azure Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
I
Intezer
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
P
Privacy & Cybersecurity Law Blog
T
The Blog of Author Tim Ferriss
I
InfoQ
C
Cybersecurity and Infrastructure Security Agency CISA
大猫的无限游戏
大猫的无限游戏
F
Full Disclosure
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Microsoft Security Blog
Microsoft Security Blog
博客园 - 三生石上(FineUI控件)
L
LINUX DO - 热门话题
V
Vulnerabilities – Threatpost
S
SegmentFault 最新的问题
人人都是产品经理
人人都是产品经理
G
GRAHAM CLULEY
A
Arctic Wolf
P
Privacy International News Feed

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Stop hardcoding! Use AWS Parameter Store instead (Hands-On)
Ahmed Srebre · 2026-04-26 · via DEV Community

Stop hardcoding! Use AWS Parameter Store instead (Hands-On)

This article is a practical guide for DevOps engineers who want to manage configuration and secrets the right way on AWS.

Figure 1: With and without Parameter Store

Introduction

If you have a database hostname, a password, and an API URL your application needs to call, where do you put them? The wrong answer is “environment variables hardcoded into your Lambda function”. The issue is: different environments (dev, prod) need different values, rotating a password means redeploying every service that uses it, and hardcoding config eventually ends up in Git (you don’t want that, trust me).

AWS has multiple services for managing configuration and secrets, but today we will focus on AWS Systems Manager Parameter Store.

AWS Parameter Store gives you a central, secure, hierarchical place to store configuration and secrets, and any AWS service can read from it at runtime without you changing a line of application code. Think of it as a managed configuration database where you store both, plain config values and encrypted secrets, organized in a folder-like structure.

In this article, we will create a set of parameters in Parameter Store and build a Lambda function that uses them. Changing a parameter value will change what the Lambda does, with no redeployment needed.

Prerequisites

  1. Create an AWS Account.

  2. Console access with permissions for: System Manager, Lambda, and IAM.

    **NOTE: **Everything in this guide is free or within free tier limits.

What is AWS System Manager Parameter Store?

Per AWS, Parameter Store is a tool in AWS Systems Manager that provides secure, hierarchical storage for configuration data management and secrets management. You can store data such as passwords, database strings, Amazon Machine Image (AMI) IDs, and license codes as parameter values. You can store values as plain text or encrypted data. You can reference Systems Manager parameters in your scripts, commands, SSM documents, and configuration and automation workflows by using the unique name that you specified when you created the parameter.

Parameter Types

Parameter Store supports three types of values:

  1. String — plain text. Use this for non-sensitive config like hostnames, URLs, or feature flag values.

  2. StringList — a comma-separated list of strings. Useful for storing a list of IPs, ARNs, or environment names in a single parameter.

  3. SecureString — the value is encrypted at rest using AWS KMS. Use this for passwords, tokens, and any sensitive data.

Parameter Tiers

Parameter Store has different size limits for parameter values depending on the parameter tier you use. Standard parameters: Maximum value size of 4 KB, and Advanced parameters: Maximum value size of 8 KB.

Hierarchy

Parameters are organized using forward-slash paths — similar to a file system:

/myapp/dev/db_host
/myapp/dev/api_url
/myapp/prod/db_host
/myapp/prod/api_url

Enter fullscreen mode Exit fullscreen mode

This makes it easy to retrieve all configuration for a specific environment at once, and it simplifies IAM policies — you can grant access to **/myapp/prod/ **without listing every individual parameter.

Key Characteristics

  • Free on the Standard tier — no per-parameter cost

  • Encrypted secrets using AWS KMS (SecureString type)

  • Full version history — every update creates a new version

  • Tight integration with Lambda, ECS, CloudFormation, and CodePipeline

  • Write operations (create, update, delete) are logged in AWS CloudTrail by default. Read operations require enabling data event logging in CloudTrail separately.

Parameter Store vs AWS Secrets Manager

AWS has more than one service that can store configuration and secrets. Before jumping into the hands-on, it is worth understanding where Parameter Store fits and when you should reach for something else.

**Secrets Manager** is the other AWS service most commonly compared to Parameter Store. Both can store secrets, but they are designed for different needs.

Figure 2: Parameter Store vs Secrets Manager, custom table

Use Parameter Store for configuration and static secrets. Use Secrets Manager when you need automatic credential rotation — database passwords, API keys that expire, and OAuth tokens.

Parameter Store vs AWS AppConfig

AppConfig is a separate service built on top of Parameter Store, designed specifically for feature flags and application configuration with deployment controls.

AppConfig is a separate service built on top of Parameter Store, designed specifically for feature flags and application configuration with deployment controls.

Choose AppConfig when you need:

  • Gradual rollouts (deploy config to 10% of instances first, then 100%)

  • Automatic rollback if a bad config causes errors

  • Configuration validation before deployment

Choose Parameter Store when you need:

  • Simple key-value config without deployment strategy complexity

  • Secrets (AppConfig is not designed for sensitive values)

  • Free storage with no additional overhead

Creating the Parameters

We will create three parameters that our Lambda function will use. They cover the most common types you will encounter in real projects.

Parameter I — Database hostname (string)

A plain-text configuration value. Nothing sensitive, so no encryption needed.

  1. Go to **Parameter Store **in the console

  2. Click Create parameter

  3. Fill in:

Name: /myapp/dev/db_host

Description: Database hostname for myapp dev environment

Tier: Standard

Type: String

Value: dev-db.ahmed.com

Data type: text

  1. Add tags: Environment = dev, App = myapp

  2. Click Create parameter

Figure 3: Create db_host String type

Parameter II — API URL (String)

This is the parameter the Lambda function will actively read and act on. The function will call whatever URL is stored there. Change the URL, the Lambda will call a different endpoint on the next run — no code change needed.

  1. Go to **Parameter Store **in the console

  2. Click Create Parameter

  3. Fill in

Name: /myapp/dev/api_url

Description: API endpoint the application calls

Tier: Standard

Type: String

Value: https://jsonplaceholder.typicode.com/posts/1

Data type: text

  1. Add tags: Environment = dev, App = myapp

  2. Click Create parameter

    NOTE: JSONPlaceholder is free public REST API for testing — no account or API key needed.

Figure 4: Create api_url String type

What have we created?

We created three parameters, and they are all for dev. Search for **/myapp/dev/ **in the Parameter Store list. All three parameters appear together, filtered by their path prefix.

In a real application, this means one API call loads all configuration for an environment — your app asks for */myapp/dev/ **and gets back every key under that path at once. For example, if we promote to production, it reads */myapp/prod/ **instead. Same code, different parameters

Figure 5: Created parameters

Using the Parameters — Lambda function

Now we put the parameters to work. The Lambda function will:

  1. Read /myapp/dev/db_host and /myapp/dev/api_url from Parameter Store in a single call

    1. Make a real HTTP request to the API URL
    2. Return the database host and the API response together

Step I — Create the Lambda function

  1. Go to **AWS Console >Lambda >Create function**

  2. Select Author from scratch

  3. Fill in:

**Function name: **parameter-store-demo

Runtime: Python 3.14

  1. Leave permissions as default and click Create function

Figure 6: Create Lambda function

Step II — Grant Permission to read from Parameter store

By default the Lambda execution role only has CloudWatch Logs access. We need to add SSM read permission.

  1. Click the Configuration tab > Permissions > Edit

Figure 7: Configuration tab > Permissions > Edit

  1. Click View role details in IAM

Figure 8: View role details in IAM

  1. Click Add permissions > Attach policies

  2. Search for AmazonSSMReadOnlyAccess and attach it

Figure 9: Attach AmazonSSMReadOnlyAccess

Step III — Write the code

  1. Click the Code tab in Lambda

    1. Replace the entire contents of lambda_function.py with:

    import boto3
    import urllib.request
    import json

    def lambda_handler(event, context):
    ssm = boto3.client('ssm')

    # Load two parameters in a single API call
    result = ssm.get_parameters(
        Names=['/myapp/dev/db_host', '/myapp/dev/api_url']
    )
    
    # Build a simple config dict from the results
    config = {p['Name'].split('/')[-1]: p['Value'] for p in result['Parameters']}
    
    # Make a real HTTP request to the URL from Parameter Store
    with urllib.request.urlopen(config['api_url']) as response:
        api_data = json.loads(response.read())
    
    return {
        'db_host': config['db_host'],
        'url_called': config['api_url'],
        'api_response': api_data
    }
    

    NOTE: get_parameters (plural) fetches multiple parameters in one API call — more efficient than calling get_parameter once per value.
    The code has no hardcoded URLs or hostnames. It asks Parameter Store, then acts on whatever it gets back.
    Important: Lambda and the parameters must be in the same AWS region. A region mismatch produces a ParameterNotFound error even if the parameter name is correct.

Step IV — Test

  1. Click Deploy to deploy the code

  2. Click Test to create the test

Figure 10: Click Deploy and then Test

  1. Create new test event and name it test

Figure 11: Create new test event

  1. Save it and click the Invoke

Figure 12: Creating the test event

  1. The Lambda loaded both parameters and returned a real API response. No hardcoded values anywhere in the code. Which means, everything is working correctly.

Figure 13: Lambda function output

Update the API URL

This is where Parameter Store shows its value. We will update both parameters — the Lambda behavior changes instantly, with no redeployment.

Update the API URL:

  1. Go to Parameter Store > /myapp/dev/api_url

  2. Click Edit >change the value to https://jsonplaceholder.typicode.com/posts/5

  3. Click Save changes

Update the database host (simulating a failover to a new database server):

  1. Open /myapp/dev/db_host

  2. Click Edit >change the value to dev-db.ahmed.srebrenica.com

  3. Click Save changes

Now open either parameter and click the History tab and you will see Version 1 and Version 2 with timestamps. Parameter Store keeps a full history of every change automatically.

Figure 14: api_url — history tab

Figure 15: db_host — history tab

Back in Lambda, click Test again:

Figure 16: Output after update

Both values updated! The Lambda code is identical to what we deployed. This is the core value of Parameter Store — application’s behavior is controlled by configuration, not by code.

Best practices

The hands-on above uses shortcuts that are fine for a demo, but shouldn’t go into production. Here is what to do differently in a real environment.

  1. Never use broad managed policies on your roles

In this hands-on, we attached AmazonSSMReadOnlyAccess to the Lambda role for convenience. In production, this is too permissive; it grants read access to every parameter in your account, including parameters that belong to other applications or contain sensitive data. Instead, create a custom inline policy scoped to only the path your function needs.

2. Always encrypt sensitive values with SecureString

Any parameter that contains a password, token, API key, or any value you would not want to expose in logs should be stored as SecureString, not String. SecureString encrypts the value at rest using AWS KMS.

For production, go one step further: use a **customer-managed KMS key (CMK) instead of the default **alias/aws/ssm. A CMK gives you full control; you can rotate the key, restrict which roles can use it, and audit every decrypt operation.

3. Never log parameter values

The application will read SecureString parameters and decrypt them. Make sure those values never appear in CloudWatch Logs. A single **print(password) **or an unhandled exception that dumps local variables can expose your secrets in plain text in your log stream.

4. Design your naming hierarchy before you start

It is much harder to rename parameters after services depend on them. Agree on a convention before you create the first parameter:

/team/environment/service/key
/platform/prod/payments/db_host
/platform/prod/payments/api_url

Enter fullscreen mode Exit fullscreen mode

A consistent hierarchy makes IAM policies easier, bulk reads cleaner, and environment promotion predictable.

5. Tag Every Parameter

Tags make it easy to understand who owns a parameter, filter by environment, and set up cost allocation:

  • Environment = prod

  • App = payments

  • Team = backend

  • ManagedBy = terraform (if using IaC)

Conclusion

In this article, we went from zero to a working Parameter Store setup entirely from the AWS Console.

We created two parameters, a database hostname and an API URL — organized under a **/myapp/dev/ **hierarchy. We then built a Lambda function that reads both parameters at runtime and makes a real HTTP request to the URL stored in Parameter Store. Finally, we updated both parameters and ran Lambda again without touching a single line of code, the behavior changed instantly.

That last step is the whole point. Application stops caring about specific values. It asks Parameter Store, and you control the answer from one central place.

A few things to take with you:

  • The hierarchy (/app/env/key) is not optional — design it from day one, it makes environment promotion and IAM policies much easier.

  • SecureString exists for anything sensitive — passwords, tokens, API keys — encrypted at rest with KMS.

  • The Standard tier is free — there is no reason not to start using this today.

  • All parameter changes are logged in CloudTrail — every update is auditable.

If you like this story, please clap and follow me.
Check out my website for basic information about me: ahmedsrebrenica.com.