Infisical will assume the provided role in your AWS account securely, without the need to share any credentials.

Self-Hosted Instance
Self-Hosted Instance
To connect your self-hosted Infisical instance with AWS, you need to set up an AWS IAM User account that can assume the configured AWS IAM Role.If your instance is deployed on AWS, the aws-sdk will automatically retrieve the credentials. Ensure that you assign the provided permission policy to your deployed instance, such as ECS or EC2.The following steps are for instances not deployed on AWS:
1
Create an IAM User
Navigate to Create IAM User in your AWS Console.
2
Create an Inline Policy
Attach the following inline permission policy to the IAM User to allow it to assume any IAM Roles:
3
Obtain the IAM User Credentials
Obtain the AWS access key ID and secret access key for your IAM User by navigating to IAM > Users > [Your User] > Security credentials > Access keys.





4
Set Up Connection Keys
- Set the access key as INF_APP_CONNECTION_AWS_ACCESS_KEY_ID.
- Set the secret key as INF_APP_CONNECTION_AWS_SECRET_ACCESS_KEY.
1
Create the Managing User IAM Role for Infisical
-
Navigate to the Create IAM Role page in your AWS Console.
- Select AWS Account as the Trusted Entity Type.
- Select Another AWS Account and provide the appropriate Infisical AWS Account ID: use 381492033652 for the US region, and 345594589636 for the EU region. This restricts the role to be assumed only by Infisical. If self-hosting, provide your AWS account number instead.
- (Recommended) Enable “Require external ID” and input your Organization ID to strengthen security and mitigate the confused deputy problem.
When configuring an IAM Role that Infisical will assume, it’s highly recommended to enable the “Require external ID” option and specify your Organization ID.This precaution helps protect your AWS account against the confused deputy problem, a potential security vulnerability where Infisical could be tricked into performing actions on your behalf by an unauthorized actor.
2
Add Required Permissions to the IAM Role
Navigate to your IAM role permissions and click Create Inline Policy.
Depending on your use case, add one or more of the following policies to your IAM Role:

AWS Secrets Manager
AWS Secrets Manager
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Secrets Manager:

If using a custom KMS key, be sure to add the IAM user or role as a key user. 

AWS Parameter Store
AWS Parameter Store
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:

If using a custom KMS key, be sure to add the IAM user or role as a key user. 

3
Copy the AWS IAM Role ARN

4
Setup AWS Connection in Infisical
-
Navigate to the App Connections tab on the Organization Settings page.
-
Select the AWS Connection option.
-
Select the Assume Role method option and provide the AWS IAM Role ARN obtained from the previous step and press Connect to AWS.
-
Your AWS Connection is now available for use.