Skip to main content

SSM Parameter Store

Quick summary: Free, hierarchical config/secret store. No auto-rotation. Best for application configuration and lower-sensitivity secrets.

See also: Secrets Manager vs SSM Parameter Store for a detailed comparison.


What Is Parameter Store?

Parameter Store is a centralized, hierarchical configuration management service. Think of it as a key-value store organized in folders β€” like a filesystem for configuration.


Parameter Types & Tiers

Types

TypeEncryptionUse CaseExample
StringNoneURLs, feature flags, configjdbc:mysql://db.example.com:3306/mydb
StringListNoneComma-separated valuesus-east-1,eu-west-1,ap-southeast-1
SecureStringKMS encryptedPasswords, API keysSuperSecret123!

Tiers

FeatureStandardAdvanced
Max size4 KB8 KB
Max parameters10,000100,000
Parameter policiesβŒβœ… (expiration, notification)
Throughput40 TPS (default)Up to 10,000 TPS
CostFree$0.05/month per parameter
Higher throughputExtra chargeIncluded

Hierarchical Organization

/ (root)
β”œβ”€β”€ prod/
β”‚ β”œβ”€β”€ myapp/
β”‚ β”‚ β”œβ”€β”€ db-url String
β”‚ β”‚ β”œβ”€β”€ db-password SecureString (KMS encrypted)
β”‚ β”‚ β”œβ”€β”€ db-port String
β”‚ β”‚ β”œβ”€β”€ feature-flags StringList
β”‚ β”‚ └── api-key SecureString
β”‚ └── shared/
β”‚ β”œβ”€β”€ cors-origins StringList
β”‚ └── jwt-secret SecureString
β”œβ”€β”€ staging/
β”‚ └── myapp/
β”‚ β”œβ”€β”€ db-url String
β”‚ └── db-password SecureString
└── dev/
└── myapp/
β”œβ”€β”€ db-url String
└── db-password SecureString

Benefits of Hierarchy

  • GetParametersByPath β€” load all config for an environment in one call
  • IAM scoping β€” restrict access by path prefix
  • Environment isolation β€” same parameter names, different paths
// IAM policy: Allow dev team access only to /dev/ parameters
{
"Effect": "Allow",
"Action": ["ssm:GetParameter*"],
"Resource": "arn:aws:ssm:us-east-1:123456789012:parameter/dev/*"
}

Java SDK Integration

Lambda β€” Load Config at Init Time

public class OrderHandler implements RequestHandler<APIGatewayProxyRequestEvent, APIGatewayProxyResponseEvent> {

private static final SsmClient SSM = SsmClient.create();
private static final Map<String, String> CONFIG;

// Load ALL config at init time (runs once per cold start)
static {
GetParametersByPathResponse response = SSM.getParametersByPath(
GetParametersByPathRequest.builder()
.path("/prod/myapp/")
.withDecryption(true)
.recursive(true)
.build());

CONFIG = response.parameters().stream()
.collect(Collectors.toMap(
p -> p.name().substring(p.name().lastIndexOf('/') + 1), // Extract param name
Parameter::value));
}

public APIGatewayProxyResponseEvent handleRequest(APIGatewayProxyRequestEvent event, Context context) {
String dbUrl = CONFIG.get("db-url");
String apiKey = CONFIG.get("api-key");
// Use cached config β€” no SSM calls on warm invocations
}
}

ECS Task Definition

{
"containerDefinitions": [{
"name": "myapp",
"secrets": [
{
"name": "DB_PASSWORD",
"valueFrom": "arn:aws:ssm:us-east-1:123:parameter/prod/myapp/db-password"
},
{
"name": "API_KEY",
"valueFrom": "arn:aws:ssm:us-east-1:123:parameter/prod/myapp/api-key"
}
]
}]
}

CloudFormation Integration

# Method 1: Parameter section (String/StringList only, NOT SecureString)
Parameters:
DbUrl:
Type: AWS::SSM::Parameter::Value<String>
Default: /prod/myapp/db-url

# Method 2: Dynamic references (works with ALL types including SecureString)
Resources:
MyRdsInstance:
Type: AWS::RDS::DBInstance
Properties:
Engine: mysql
# String parameter
DBName: "{{resolve:ssm:/prod/myapp/db-name}}"
# SecureString parameter (MUST use ssm-secure)
MasterUserPassword: "{{resolve:ssm-secure:/prod/myapp/db-password:1}}"
# Secrets Manager
# MasterUserPassword: "{{resolve:secretsmanager:prod/db-secret:SecretString:password}}"

Parameter Policies (Advanced Tier)

// Expiration: Delete parameter after date
{
"Type": "Expiration",
"Version": "1.0",
"Attributes": { "Timestamp": "2025-12-31T00:00:00.000Z" }
}

// Notification before expiration
{
"Type": "ExpirationNotification",
"Version": "1.0",
"Attributes": { "Before": "15", "Unit": "Days" }
}

// Alert if not updated for N days
{
"Type": "NoChangeNotification",
"Version": "1.0",
"Attributes": { "After": "90", "Unit": "Days" }
}

SecureString & KMS

Reading a SecureString requires TWO permissions:

{
"Effect": "Allow",
"Action": [
"ssm:GetParameter", // Permission to read the parameter
"kms:Decrypt" // Permission to decrypt with the KMS key
],
"Resource": [
"arn:aws:ssm:us-east-1:123:parameter/prod/myapp/*",
"arn:aws:kms:us-east-1:123:key/my-key-id"
]
}

Parameter Store vs Environment Variables

FeatureSSM Parameter StoreLambda Env Variables
Max size4-8 KB per param4 KB total
EncryptionKMS (SecureString)KMS (optional)
Centralizedβœ… Shared across functions❌ Per-function
Versioningβœ…βŒ
Hierarchyβœ…βŒ
Dynamic updatesβœ… (next cold start)❌ (redeploy required)
CostFree (Standard)Free

DVA-C02 Exam Tips

SSM Parameter Store Exam Cheat Sheet
  1. Free for Standard tier (up to 10,000 parameters)
  2. SecureString needs BOTH ssm:GetParameter AND kms:Decrypt permissions
  3. CloudFormation SecureString = MUST use {{resolve:ssm-secure:...}}
  4. GetParametersByPath = load all config under a path prefix in one call
  5. No auto-rotation β€” use custom Lambda or Secrets Manager instead
  6. Advanced tier = parameter policies (expiration, notification)
  7. ECS secrets can reference SSM parameters directly
  8. Hierarchy enables IAM path-based access control

Practice Questions

Q1. CloudFormation template needs SecureString from SSM. How?

A) AWS::SSM::Parameter::Value<SecureString>
B) {{resolve:ssm-secure:/path/to/param}}
C) Direct string in template
D) Custom resource

βœ… Answer & Explanation

B β€” SecureString in CloudFormation requires dynamic references with ssm-secure. The Parameters section doesn't support SecureString type.


Q2. App needs auto-rotating DB password. Which service?

A) Secrets Manager
B) SSM Parameter Store
C) KMS
D) IAM

βœ… Answer & Explanation

A β€” Secrets Manager has native auto-rotation for RDS. SSM Parameter Store has no built-in rotation.


Q3. Lambda reads SecureString but gets AccessDeniedException. Role has ssm:GetParameter. What's missing?

A) ssm:DescribeParameters
B) kms:Decrypt on the KMS key
C) ssm:GetParameters
D) VPC endpoint

βœ… Answer & Explanation

B β€” SecureString is encrypted with KMS. The role needs both ssm:GetParameter AND kms:Decrypt.


Resources

πŸ“–
Track Page Progress0 / 635 Read
Knowledge Base Completion0%