---
title: Secret Management w/ Spring Cloud and AWS Parameter Store
description: "Today's applications are broken into smaller and smaller pieces. We've been\nslowly transitioning away from managing our own infrastructure; from using\nvirtual instances to deploying to clusters. Your environment may have one or\nmore clusters. Those clusters have many services. Those services have many\ntasks. Each task is an application"
image: https://blog.ippon.tech/hubfs/Imported_Blog_Media/aws-param-store-splash-3.png
---

[Skip to main content](https://blog.ippon.tech/secret-management-spring-cloud-and-aws-parameter-store#main)

[![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=219&height=64&name=IpponLogoKleinBlue.png) ![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=219&height=64&name=IpponLogoKleinBlue.png) ![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=168&height=49&name=IpponLogoKleinBlue.png) ![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=168&height=49&name=IpponLogoKleinBlue.png)](https://ipponusa.com/)

- [Home](https://ipponusa.com)
- [Show submenu for About About](https://ipponusa.com/about-us) 
    - [Who We Are](https://ipponusa.com/who-we-are)
    - [Careers](https://ipponusa.com/careers)
    - [Show submenu for Our Partners Our Partners](https://ipponusa.com/our-partners/) 
          - [AWS](https://ipponusa.com/our-partners/aws/)
          - [Snowflake](https://ipponusa.com/our-partners/snowflake/)
          - [Databricks](https://ipponusa.com/our-partners/databricks/)
          - [Microsoft](https://ipponusa.com/our-partners/microsoft/)
- [Show submenu for Services Services](https://ipponusa.com/services) 
    - [Snowflake](https://ipponusa.com/service/snowflake-concierge/)
    - [Artificial Intelligence](https://ipponusa.com/service/artificial-intelligence/)
    - [Data & Analytics](https://ipponusa.com/service/data-analytics/)
    - [Cloud Strategy](https://ipponusa.com/service/cloud-strategy/)
    - [Platform Modernization](https://ipponusa.com/service/platform-moderization/)
    - [Product Innovation](https://ipponusa.com/service/product-innovation/)
    - [Operating Model](https://ipponusa.com/service/operating-model/)
- [Blogs](https://blog.ippon.tech/)
- [Success Stories](https://ipponusa.com/success-stories/)
- [Show submenu for Resources Resources](https://ipponusa.com/resources/) 
    - [eBooks](https://ipponusa.com/ebooks/)
    - [The Data Pour](https://info.ippon.tech/the-data-pour)
    - [Videos & Webinars](https://info.ippon.tech/videos-and-webinars)
    - [Media Center](https://ipponusa.com/media-center/)

Search

Open main navigation

Close main navigation

- [Home](https://ipponusa.com)
- Show submenu for About About 
  
    - About
    - [About](https://ipponusa.com/about-us)
    - [Who We Are](https://ipponusa.com/who-we-are)
    - [Careers](https://ipponusa.com/careers)
    - Show submenu for Our Partners Our Partners 
      
          - Our Partners
          - [Our Partners](https://ipponusa.com/our-partners/)
          - [AWS](https://ipponusa.com/our-partners/aws/)
          - [Snowflake](https://ipponusa.com/our-partners/snowflake/)
          - [Databricks](https://ipponusa.com/our-partners/databricks/)
          - [Microsoft](https://ipponusa.com/our-partners/microsoft/)
- Show submenu for Services Services 
  
    - Services
    - [Services](https://ipponusa.com/services)
    - [Snowflake](https://ipponusa.com/service/snowflake-concierge/)
    - [Artificial Intelligence](https://ipponusa.com/service/artificial-intelligence/)
    - [Data & Analytics](https://ipponusa.com/service/data-analytics/)
    - [Cloud Strategy](https://ipponusa.com/service/cloud-strategy/)
    - [Platform Modernization](https://ipponusa.com/service/platform-moderization/)
    - [Product Innovation](https://ipponusa.com/service/product-innovation/)
    - [Operating Model](https://ipponusa.com/service/operating-model/)
- [Blogs](https://blog.ippon.tech/)
- [Success Stories](https://ipponusa.com/success-stories/)
- Show submenu for Resources Resources 
  
    - Resources
    - [Resources](https://ipponusa.com/resources/)
    - [eBooks](https://ipponusa.com/ebooks/)
    - [The Data Pour](https://info.ippon.tech/the-data-pour)
    - [Videos & Webinars](https://info.ippon.tech/videos-and-webinars)
    - [Media Center](https://ipponusa.com/media-center/)
- Search
- [Contact Us](https://ipponusa.com/contact/)

[Contact Us](https://ipponusa.com/contact/)

# Secret Management w/ Spring Cloud and AWS Parameter Store

![John Strickler](https://app.hubspot.com/settings/avatar/d41d8cd98f00b204e9800998ecf8427e)

 by [John Strickler](https://blog.ippon.tech/author/john-strickler)

July 9, 2020

![Secret Management w/ Spring Cloud and AWS Parameter Store](https://blog.ippon.tech/hubfs/Imported_Blog_Media/aws-param-store-splash-3.png)

[Secrets Management](https://blog.ippon.tech/tag/secrets-management/) [Spring Boot](https://blog.ippon.tech/tag/spring-boot/) [Spring Cloud](https://blog.ippon.tech/tag/spring-cloud/) [AWS Parameter Store](https://blog.ippon.tech/tag/aws-parameter-store/) [Elastic Container Service](https://blog.ippon.tech/tag/elastic-container-service/) [Cloud](https://blog.ippon.tech/tag/cloud/) [AWS ECS](https://blog.ippon.tech/tag/aws-ecs/)

 

July 9, 2020

Today's applications are broken into smaller and smaller pieces. We've been slowly transitioning away from managing our own infrastructure; from using virtual instances to deploying to clusters. Your environment may have one or more clusters. Those clusters have many services. Those services have many tasks. Each task is an application running in its own container. And more than likely, that application requires **configuration**.

I want to share with you a simple way to store your sensitive configuration and to have your application retrieve it at startup. This solution is appealing because there's no infrastructure to manage, has little maintenance, and scales beautifully. So let's get started.

## Storing your configuration

For a contrived example, I'll store a *GitHub Token* in AWS Parameter Store and make it available to our Spring Boot application.

### Pre-reqs

What you need to get started, or most likely, what you already have in place:

- A **Spring Boot** application
- Deployed on **AWS**

### Store your secrets in AWS Parameter Store

Open up **AWS Systems Manager** then go to **Parameter Store** under **Application Management**.

- Click `Create Parameter`.
- In the *name* field, enter `/config/application/github.token`.
- In the *description* field, enter `GitHub API Token`
- Select `SecureString` from the *type* field. Accept the default KMS key source.
- In the *text* field, enter `ABC123`.
- Click `Create Parameter` to save it.

![Create Parameter Screenshot](https://blog.ippon.tech/hubfs/Imported_Blog_Media/aws-param-store-create-parameter-2.png)

A few things to note, for the *type* field I could have used a String but instead I chose **SecureString** to keep the value encrypted at rest. You can do either, and it will be transparently decrypted when it is retrieved. For the *name* field, the prefix `/config/application/` is important but everything else is just made up. I'll go into why the prefix is important in just a bit.

### Retrieving Secrets

The "secret" sauce of this solution is in the integration. Now that your configuration is securely stored in AWS, you need a reliable way to retrieve it. A poor way to integrate would be to specifiy each property in the ECS task definition using ValueFrom mappings. That ends up requiring more configuration with more to maintain. Unsurprisingly, there's a great Spring integration that can help us out called **Spring Cloud Starter AWS Parameter Store Config**.

### Add the Spring Boot starter dependency

In your application's pom.xml, add:

```
<dependency>
  <groupId>org.springframework.cloud</groupId>
  <artifactId>spring-cloud-starter-aws-parameter-store-config</artifactId>
</dependency>
```

Additionally, if Spring Cloud isn't set up in the project yet, add the following to the pom.xml as well:

```
<project>
   ...

  <properties>
    ...
    <!-- This is the latest version as of the 7/7/2020 -->
    <spring-cloud.version>Hoxton.SR6</spring-cloud.version> 
  </properties>
   
  <dependencyManagement>
    <dependencies>
      <dependency>
        <groupId>org.springframework.cloud</groupId>
        <artifactId>spring-cloud-dependencies</artifactId>
        <version>${spring-cloud.version}</version>
        <type>pom</type>
        <scope>import</scope>
      </dependency>
    </dependencies>
  </dependencyManagement>

</project>
```

### Deploy

**That's it!** And now, there is some magic happening as is the case with most Spring integrations.

Deploy your application to AWS and Spring Cloud will access the Parameter Store on AWS. Properties are retrieved and injected based on the following **prefix** conventions:

- `/config/application/` - applies to all applications
- `/config/application_dev/` - applies to all applications with an active `dev` profile
- `/config/my-api/` - applies to only the `my-api` application (defined by `spring.application.name` in your application properties)
- `/config/my-api_dev/` - applies to only the `my-api` application with an active `dev` profile

These conventions provide the flexibility to define global, application-specific, and environment-specific parameters. An added benefit is that parameters can be added/changed/removed in AWS Parameter Store and will sync on application restart. There's no middle layers or task definitions to update.

### Access the injected property

The `github.token` property should now be retrieved at application startup from Parameter Store. The parameter's full key is `/config/application/github.token`. The prefix, `/config/application`, is omitted and what is left is our application property key. The value, `ABC123`, is transparently decrypted and provided to the application at runtime.

## Wrapping Up

If this seems simple, it's because it is! Spring Boot's starter packages tend to do a good job out-of-the-box with little to no configuration.

I hope you found this to be easy to follow and beneficial. And remember, keep your secrets out of your source code!

## Related Articles

##### [![Rehosting Made Easy with AWS MGN](https://blog.ippon.tech/hs-fs/hubfs/Blockchain-Dec-01-2024-06-59-49-3912-PM.png?width=520&height=294&name=Blockchain-Dec-01-2024-06-59-49-3912-PM.png) Azure • March 20, 2026 Rehosting Made Easy with AWS MGN 12 min read](https://blog.ippon.tech/exploring-rehosting-with-aws-mgn)

##### [![Current-State First: Understanding Your Infrastructure Is Critical for a Successful Cloud Migration](https://blog.ippon.tech/hs-fs/hubfs/shutterstock_2161779273.jpg?width=520&height=294&name=shutterstock_2161779273.jpg) Cloud • March 19, 2026 Current-State First: Understanding Your Infrastructure Is Critical for a Successful Cloud Migration 8 min read](https://blog.ippon.tech/understanding-the-current-state)

##### [![AWS re:Invent 2025: Understanding the Event and the Major Innovations That Will Transform the Cloud](https://blog.ippon.tech/hs-fs/hubfs/Ippon%20copy%202.jpg?width=520&height=294&name=Ippon%20copy%202.jpg) Serverless • December 11, 2025 AWS re:Invent 2025: Understanding the Event and the Major Innovations That Will Transform the Cloud 9 min read](https://blog.ippon.tech/aws-reinvent-2025-understanding-the-event-and-the-major-innovations-that-will-transform-the-cloud)

### Comments

### Subscribe to Our Blog!

Stay informed with the latest insights and updates by signing up for our weekly blog newsletter – delivered straight to your inbox!

[Back to blog homepage »](https://blog.ippon.tech/)

![IpponLogoKleinBlue](https://blog.ippon.tech/hs-fs/hubfs/IpponLogoKleinBlue.png?width=247&height=73&name=IpponLogoKleinBlue.png "IpponLogoKleinBlue")

Ippon is a consulting and expertise firm, who is convinced that technology is a source of progress for society. We help our clients leverage their digital assets to design an appropriate strategy and deploy their transformation roadmap at scale.

#### Navigation

- [Home](https://ipponusa.com/)
- [About](https://ipponusa.com/about-us/)
- [Services](https://ipponusa.com/services/)
- [Blogs](https://blog.ippon.tech/?__hstc=223043268.1036d82247623b329dfefe4e92697801.1714729179243.1714729179243.1714729179243.1&__hssc=223043268.2.1714729179244&__hsfp=803678701)
- [eBooks](https://ipponusa.com/ebooks/)
- [The Data Pour](https://info.ippon.tech/the-data-pour?__hstc=223043268.1036d82247623b329dfefe4e92697801.1714729179243.1714729179243.1714729179243.1&__hssc=223043268.2.1714729179244&__hsfp=803678701)

[Contact Us](https://ipponusa.com/contact/)

[Join Us](https://ipponusa.com/careers/)

#### Services

- [Data & Analytics](https://ipponusa.com/service/data-analytics/)
- [Cloud Strategy](https://ipponusa.com/service/cloud-strategy/)
- [Artificial Intelligence](https://ipponusa.com/service/artificial-intelligence/)
- [Operating Model](https://ipponusa.com/service/operating-model/)
- [Platform Modernization](https://ipponusa.com/service/platform-moderization/)
- [Product Innovation](https://ipponusa.com/service/product-innovation/)

#### Ippon International

- [France](https://fr.ippon.tech/?__hstc=223043268.1036d82247623b329dfefe4e92697801.1714729179243.1714729179243.1714729179243.1&__hssc=223043268.2.1714729179244&__hsfp=803678701)
- [Australia](https://au.ippon.tech/?__hstc=223043268.1036d82247623b329dfefe4e92697801.1714729179243.1714729179243.1714729179243.1&__hssc=223043268.2.1714729179244&__hsfp=803678701)

- #### Contact
- Ippon Technologies  
  [3431 West Leigh Street Richmond, VA 23230, USA](https://maps.app.goo.gl/RySm6SAwZnsxeiLz9)
- [(844) 477- 6687](tel:8444776687)
- [Sales@ipponusa.com](mailto:Sales@ipponusa.com)

<https://www.facebook.com/IpponUSA/> <https://www.youtube.com/c/ipponusa> <https://www.linkedin.com/company/ippon-technology>

©Copyright 2024 Ippon USA. All Rights Reserved.   |   [Terms and Conditions](https://ipponusa.com/privacy-policy/)   |   [Privacy Policy](https://ipponusa.com/privacy-policy/)   |   [Website by Skol Marketing](https://skolmarketing.com/)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "John Strickler",
    "url" : "https://blog.ippon.tech/author/john-strickler"
  },
  "dateModified" : "2024-01-29T16:52:35.893Z",
  "datePublished" : "2020-07-09T12:46:00.000Z",
  "headline" : "Secret Management w/ Spring Cloud and AWS Parameter Store",
  "image" : [ "https://blog.ippon.tech/hubfs/Imported_Blog_Media/aws-param-store-splash-3.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.ippon.tech/secret-management-spring-cloud-and-aws-parameter-store",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.ippon.tech/hubfs/logo_SVG.svg"
    },
    "name" : "Ippon Technologies"
  }
}
```