---
title: "Deep Health Checks Without the Risk: HMAC Signing in Guardian"
description: Secure deep health checks with HMAC signing in Guardian, an open-source AWS monitoring tool. Get full diagnostic detail without exposing internals.
image: https://blog.base2services.com/hubfs/Blog%20Thumbnails/Blog%20Feature%20Update%20v1.jpg
---

[![base2Services - The Cloud Services People](https://www.base2services.com/images/base2.svg)](https://www.base2services.com/)

- [Solutions](https://www.base2services.com/services/) 
    - Get Started Here
    - [KickOff](https://www.base2services.com/products/kickoff/)
    - [Secure Compass](https://www.base2services.com/products/securecompass/)
    - [Focused AWS Review](https://www.base2services.com/consulting/services/discovery-and-review/)
    - Managed Services
    - [Cloud Management](https://www.base2services.com/cloudmanagement/)
    - [Platform Engineering](https://www.base2services.com/platform-engineering/)
    - [Compliance & Risk](https://www.base2services.com/security/)
    - Bundled Engagement
    - [DevOps as a Service](https://www.base2services.com/devops/)
    - [Prototype to Production](https://www.base2services.com/prototype-to-production/)
    - Specialist Engagements
    - [Migration](https://www.base2services.com/consulting/services/cloud-migration/)
    - [AI Factory](https://www.base2services.com/artificialintelligence/aifactory/)
    - [Generative AI](https://www.base2services.com/artificialintelligence/generativeai/)
    - [SaaS CTO](https://www.base2services.com/consulting/services/saas-cto/)
- [Industries](https://www.base2services.com/industries/) 
    - [SaaS & ISVs](https://www.base2services.com/industries/saas-and-isvs/)
    - [Financial Services](https://www.base2services.com/industries/financial-services/)
    - [Healthcare & Life Sciences](https://www.base2services.com/industries/healthcare-and-life-sciences/)
    - [Government & Enterprise](https://www.base2services.com/industries/government-and-enterprise/)
    - [Media](https://www.base2services.com/industries/media/)
    - [Education](https://www.base2services.com/industries/education/)
- [AWS Advanced Partner](https://www.base2services.com/partners/partner-pages/aws.html) 
    - [AWS DevOps Competency](https://www.base2services.com/partners/partner-pages/aws.html)
    - [AWS SaaS Competency](https://www.base2services.com/aws-saas-solutions/index.html)
    - [Enablement Tools](https://www.base2services.com/partners/)
- [Explore](https://www.base2services.com/community/) 
    - [Blog](https://blog.base2services.com)
    - [Videos](https://www.base2services.com/community/videos/)
    - Toolkit
    - [Cloud Monitoring](https://www.base2services.com/products/cloud-monitoring-aws/)
    - [Start/Stop](https://www.base2services.com/products/start-stop-aws/)
    - [Safe Test Data](https://www.base2services.com/products/safe-test-data/)
    - [App Configuration](https://www.base2services.com/products/application-config/)
    - [Secure Access](https://www.base2services.com/products/secure-access-aws/)
    - [Ask about AWS](https://www.base2services.com/products/ai-access-aws/)
    - [Resource Documenter](https://www.base2services.com/products/resource-documenter/)
- [Talk to Us](https://www.base2services.com/contact/)
- [About](https://www.base2services.com/about/) 
    - [About Us](https://www.base2services.com/about/)
    - [Why Choose Us](https://www.base2services.com/how-we-work/why-choose-us/)
    - [How We Work](https://www.base2services.com/how-we-work/)
    - [Case Studies](https://www.base2services.com/customers/)

<https://blog.base2services.com/authenticated-health-checks-without-exposure-hmac-signing-in-cfnguardian#mobile-nav>

- [Solutions](https://www.base2services.com/services/)
  
  ##### Get Started Here
  
    - [KickOff](https://www.base2services.com/products/kickoff/)
    - [Secure Compass](https://www.base2services.com/products/securecompass/)
    - [Focused AWS Review](https://www.base2services.com/consulting/services/discovery-and-review/)

  ##### Managed Services
  
    - [Cloud Management](https://www.base2services.com/cloudmanagement/)
    - [Platform Engineering](https://www.base2services.com/platform-engineering/)
    - [Compliance & Risk](https://www.base2services.com/security/)

  ##### Bundled Engagement
  
    - [DevOps as a Service](https://www.base2services.com/devops/)
    - [Prototype to Production](https://www.base2services.com/prototype-to-production/)

  ##### Specialist Engagements
  
    - [Migration](https://www.base2services.com/consulting/services/cloud-migration/)
    - [AI Factory](https://www.base2services.com/artificialintelligence/aifactory/)
    - [Generative AI](https://www.base2services.com/artificialintelligence/generativeai/)
    - [SaaS CTO](https://www.base2services.com/consulting/services/saas-cto/)
- [Industries](https://www.base2services.com/industries/) 
    - [SaaS & ISVs](https://www.base2services.com/industries/saas-and-isvs/)
    - [Financial Services](https://www.base2services.com/industries/financial-services/)
    - [Healthcare & Life Sciences](https://www.base2services.com/industries/healthcare-and-life-sciences/)
    - [Government & Enterprise](https://www.base2services.com/industries/government-and-enterprise/)
    - [Media](https://www.base2services.com/industries/media/)
    - [Education](https://www.base2services.com/industries/education/)
- More 
    - [AWS Advanced Partner](https://www.base2services.com/partners/partner-pages/aws.html)
    - [Explore](https://www.base2services.com/community/)
    - [About Us](https://www.base2services.com/about/)
    - [Case Studies](https://www.base2services.com/customers/)
- [AWS Advanced Partner](https://www.base2services.com/partners/partner-pages/aws.html) 
    - [AWS DevOps Competency](https://www.base2services.com/partners/partner-pages/aws.html)
    - [AWS SaaS Competency](https://www.base2services.com/aws-saas-solutions/index.html)
    - [Amazon Foundational Technical Review](https://www.base2services.com/consulting/amazon-foundational-technical-review-ftr/index.html)
    - [Other partners](https://www.base2services.com/partners/)
- [Explore](https://www.base2services.com/community/) 
    - [Blog](https://blog.base2services.com)
    - [Videos](https://www.base2services.com/community/videos/)
    - Toolkit
    - [Cloud Monitoring](https://www.base2services.com/products/cloud-monitoring-aws/)
    - [Start/Stop](https://www.base2services.com/products/start-stop-aws/)
    - [Safe Test Data](https://www.base2services.com/products/safe-test-data/)
    - [App Configuration](https://www.base2services.com/products/application-config/)
    - [Secure Access](https://www.base2services.com/products/secure-access-aws/)
    - [Ask about AWS](https://www.base2services.com/products/ai-access-aws/)
    - [Resource Documenter](https://www.base2services.com/products/resource-documenter/)
- [About](https://www.base2services.com/about/) 
    - [About Us](https://www.base2services.com/about/)
    - [Why Choose Us](https://www.base2services.com/how-we-work/why-choose-us/)
    - [How We Work](https://www.base2services.com/how-we-work/)
    - [Case Studies](https://www.base2services.com/customers/)
- <https://www.base2services.com/search.html> 
    - [Search](https://www.base2services.com/search.html)
- [Talk to Us](https://www.base2services.com/contact/)

[1300 713 559](tel:1300713559) [646 586 9485](tel:3474670942)

[← Blogs](https://blog.base2services.com/)

[Tools](https://blog.base2services.com/tag/tools)

# Deep Health Checks Without the Risk: HMAC Signing in Guardian

![Jared Brook](https://blog.base2services.com/hs-fs/hubfs/Headshots/jared@2x.jpg?width=100) Jared Brook ·  6 Minute Read

Share [in](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fblog.base2services.com%2Fauthenticated-health-checks-without-exposure-hmac-signing-in-cfnguardian) [X](https://twitter.com/intent/tweet?url=https%3A%2F%2Fblog.base2services.com%2Fauthenticated-health-checks-without-exposure-hmac-signing-in-cfnguardian&text=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EDeep+Health+Checks+Without+the+Risk%3A+HMAC+Signing+in+Guardian%3C%2Fspan%3E) [f](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fblog.base2services.com%2Fauthenticated-health-checks-without-exposure-hmac-signing-in-cfnguardian) [↗](mailto:?subject=%3Cspan+id%3D%22hs_cos_wrapper_name%22+class%3D%22hs_cos_wrapper+hs_cos_wrapper_meta_field+hs_cos_wrapper_type_text%22+style%3D%22%22+data-hs-cos-general-type%3D%22meta_field%22+data-hs-cos-type%3D%22text%22+%3EDeep+Health+Checks+Without+the+Risk%3A+HMAC+Signing+in+Guardian%3C%2Fspan%3E&body=https%3A%2F%2Fblog.base2services.com%2Fauthenticated-health-checks-without-exposure-hmac-signing-in-cfnguardian)

Health checks are one of those things that seem simple until they aren't. A basic `/health` endpoint that returns `200 OK` tells you the process is running, but not much else. Is the database connection pool healthy? Are downstream dependencies responding? Is the cache warm? To answer those questions, your health endpoint needs to do real work and return real data - and that's where things get uncomfortable.

The more useful a health check response is, the more it reveals about your system's internals. Database connection strings, dependency latency figures, queue depths, cache hit rates - all valuable for diagnosing issues, all dangerous in the wrong hands. If your health endpoint is publicly reachable (and for external monitoring, it usually has to be), you've effectively published a reconnaissance guide for anyone who knows where to look.

This is the tension we kept running into with customers using our [**CfnGuardian**](https://blog.base2services.com/streamline-aws-monitoring-with-guardian), our open source AWS monitoring tool, for HTTP health checks. They wanted deep, informative checks but couldn't justify the exposure. So we built HMAC signed requests into Guardian's HTTP check Lambda.

## The Problem with Deep Health Checks

Guardian has supported HTTP health checks for a long time - hit an endpoint, verify the status code, optionally match a regex against the response body. For most services, that's enough. But for production systems where you need to understand why something is degraded, not just that it's degraded, a shallow check leaves you flying blind.

The obvious answer is to add authentication to the health endpoint. But traditional approaches come with their own headaches. API keys in headers work, but a static key that never changes and travels in every request isn't much better than no key at all. OAuth tokens add complexity that's hard to justify for a monitoring endpoint. IP whitelisting breaks the moment your monitoring runs from a new Lambda execution environment or a different availability zone.

What we needed was a signing scheme that proves the request came from Guardian, resists replay attacks, and requires zero interactive authentication. HMAC fits that model precisely.

## How It Works

When you enable HMAC signing on a Guardian HTTP check, the Lambda computes a signature for every request it sends. The signature covers the HTTP method, the URL path, a timestamp, a random nonce, the query string, and a SHA-256 hash of the request body. The shared secret used for signing lives in AWS Systems Manager Parameter Store as a SecureString, and Guardian's generated IAM role is automatically granted `ssm:GetParameter` access to that path.

Each request carries four additional headers (using a configurable prefix, defaulting to `X-Health`):

- `X-Health-Signature` - the HMAC-SHA256 hex digest of the canonical string
- `X-Health-Key-Id` - an identifier for the signing key
- `X-Health-Timestamp` - the Unix epoch time when the request was signed
- `X-Health-Nonce` - a random UUID to prevent replay

On the application side, verification is straightforward. Reconstruct the same canonical string from the incoming request, compute the HMAC with your copy of the shared secret, and compare. If you want replay protection (and you should), reject requests where the timestamp is more than a few minutes old and track nonces you've already seen.

The canonical string format is deliberately simple:

METHOD\\nPATH\\nTIMESTAMP\\nNONCE\\nQUERY\\nBODY\_HASH

No complex canonicalisation rules, no header sorting, no edge cases around URL encoding. It's designed to be easy to implement in any language your application happens to use.

## One Endpoint, Two Behaviours

One of our customers took an approach we particularly liked. Rather than creating separate endpoints for shallow and deep checks, they built a single `/health` path that behaves differently based on whether the HMAC headers are present and valid.

An unsigned request gets the standard shallow response - a `200 OK` with a minimal body. The same endpoint, when it receives valid HMAC headers from Guardian, returns a detailed JSON payload with database pool status, dependency latencies, recent error rates, and queue depths. From Guardian's perspective, it can match against both the status code and specific patterns in that rich response body using the existing `BodyRegexMatch` feature.

This pattern is clean because it doesn't require any routing changes to your application. Load balancers, CDNs, and uptime monitors that already hit `/health` keep working exactly as before. Only Guardian, with the shared secret, sees the full picture.

## Configuring It

On the Guardian side, the configuration is three lines in your YAML:

```
Resources:
  Http:
  - Id: https://api.example.com/health
    StatusCode: 200
    HmacSecretSsm: /guardian/myapp/hmac-secret
    HmacKeyId: default
    HmacHeaderPrefix: X-Health
```

`HmacSecretSsm` is the only required field - it points to the SSM parameter holding the shared secret.

`HmacKeyId` defaults to `default` and is included in the headers so your application can support key rotation (serve two keys simultaneously during a transition window).

`HmacHeaderPrefix` defaults to `X-Health` but can be changed if those header names conflict with something in your stack.

The same configuration works for internal VPC-based checks:

```
Resources:
  InternalHttp:
  - Environment: Prod
    VpcId: vpc-1234
    Subnets: [subnet-abcd]
    Hosts:
    - Id: http://api.internal/health
      StatusCode: 200
      HmacSecretSsm: /guardian/myapp/hmac-secret
```

The Lambda caches the SSM secret in memory for ten minutes across warm invocations, so you're not paying for an SSM API call on every health check cycle.

## Verifying Signatures in Your Application

Your application needs to verify the signature using the same shared secret stored in SSM. The verification logic is intentionally minimal - here's the core of it in Python:

```
import hmac, hashlib, time

def verify_guardian_request(request, secret, prefix="X-Health", max_age=300):
    signature = request.headers.get(f"{prefix}-Signature")
    key_id    = request.headers.get(f"{prefix}-Key-Id")
    timestamp = request.headers.get(f"{prefix}-Timestamp")
    nonce     = request.headers.get(f"{prefix}-Nonce")

    if not all([signature, key_id, timestamp, nonce]):
        return False

    if abs(int(timestamp) - time.time()) > max_age:
        return False

    body_hash = hashlib.sha256(request.body or b"").hexdigest()
    canonical = "\n".join([
        request.method,
        request.path,
        timestamp,
        nonce,
        request.query_string or "",
        body_hash,
    ])
    expected = hmac.new(secret.encode(), canonical.encode(), hashlib.sha256).hexdigest()
    return hmac.compare_digest(expected, signature)
```

Optionally, you can also track nonces (a short-lived cache or database table) to reject duplicates within the timestamp window. The timestamp check alone prevents the most common replay scenarios, but nonce tracking closes the gap entirely if your threat model calls for it. The `compare_digest` call is important - it performs a constant-time comparison that prevents timing attacks against the signature.

## Why Not Just Use a WAF or IP Restrictions?

It's a fair question. AWS WAF can restrict access to health endpoints, and security groups can lock down internal checks. But both approaches have practical limitations for monitoring.

WAF rules operate at the edge, which means they work well for blocking external traffic but add complexity when your monitoring Lambda runs inside the same AWS account. You end up maintaining allow-lists of IP ranges that change as Lambda execution environments rotate. Security groups help for VPC-internal checks but don't apply to public endpoints at all.

HMAC signing works regardless of network topology. The Lambda could be running in any subnet, any availability zone, any region - the signature is what proves identity, not the source IP. It's also self-contained: no external dependencies beyond SSM, no additional AWS services to configure, no firewall rules to keep in sync.

## Getting Started

If you're already running Guardian through our managed service, just reach out to your account team. We'll handle the Guardian configuration update and guide you through the endpoint changes needed on your side.

If you're managing Guardian yourself, the feature is available in [**CfnGuardian v0.12.1**](https://github.com/base2Services/cfn-guardian/releases/tag/0.12.1) and the corresponding `aws-lambda-http-check` update. Enabling it is a configuration change - no infrastructure migration required. Add your shared secret as a SecureString in SSM, point `HmacSecretSsm` at that parameter in your Guardian YAML, and implement the verification logic on your health endpoint.

New to Guardian? It's open source and free to use. Head to our [**Github repository**](https://github.com/base2Services/cfn-guardian/) to get started, and follow the setup instructions to deploy it into your AWS environment.

Deep health checks give you the diagnostic detail you actually need when something goes wrong - HMAC signing means you no longer have to choose between visibility and security.

[**Contact us**](https://www.base2services.com/contact/) if you'd like help designing deep health check strategies for your applications, or if you're interested in what Guardian can do for your monitoring stack.

#### **Further Reading**

Start with our introduction to Guardian's capabilities [**Streamline AWS Monitoring with Guardian**](https://blog.base2services.com/streamline-aws-monitoring-with-guardian) and how to [**Enhance AWS notifications with Autonomous Guardian Stacks in Slack**](https://blog.base2services.com/enhancing-aws-notifications-autonomous-guardian-stacks-in-slack).

#### Stay in the loop

### DevOps & AI insights, straight to your inbox

Our best content, services and events. Roughly every second month.

### Keep reading

#### [devops Tools base2bot Now Supports Microsoft Teams](https://blog.base2services.com/base2bot-now-supports-microsoft-teams)

#### [devops Tools Eliminate Monitoring Blind Spots: Bearse Metrics Monitor Automatically Detects Unmonitored Resources](https://blog.base2services.com/eliminate-monitoring-blind-spots-with-bearse-metrics-monitor)

#### [devops Tech · Tools · AI Enhancing AI Interactions with System Prompts for ChatGPT using Page AI](https://blog.base2services.com/system-prompts-for-chatgpt-and-pageai)

## Send an enquiry

Tell us about your environment, a project in flight or a problem you are trying to solve.

- For regulated, SaaS and product teams on AWS
- No pitch deck, a practical conversation first

Or book a time that suits you

[Book a 30-minute chat](https://info.base2services.com/meetings/m-shelton/contact-us)

[![base2Services](https://www.base2services.com/images/base2_white.svg)](https://www.base2services.com/)

<https://www.linkedin.com/company/base2services> <https://x.com/base2Services> <https://www.facebook.com/pages/base2Services/91506069748> <https://www.youtube.com/c/Base2services>

base2Services is an ISO 27001:2022 certified AWS managed services partner, running platform engineering, cloud operations, AI operations and compliance for SaaS companies, ISVs and regulated software teams since 2005.

### Get Started Here

- [KickOff](https://www.base2services.com/products/kickoff/)
- [Secure Compass](https://www.base2services.com/products/securecompass/)
- [Focused AWS Review](https://www.base2services.com/consulting/services/discovery-and-review/)

### Managed Services

- [Cloud Management](https://www.base2services.com/cloudmanagement/)
- [Platform Engineering](https://www.base2services.com/platform-engineering/)
- [Compliance & Risk](https://www.base2services.com/security/)
- [DevOps as a Service](https://www.base2services.com/devops/)

### Specialist Engagements

- [Prototype to Production](https://www.base2services.com/prototype-to-production/)
- [Migration](https://www.base2services.com/consulting/services/cloud-migration/)
- [AI Factory](https://www.base2services.com/artificialintelligence/aifactory/)
- [Generative AI](https://www.base2services.com/artificialintelligence/generativeai/)
- [SaaS CTO](https://www.base2services.com/consulting/services/saas-cto/)

### Toolkit

- [Cloud Monitoring](https://www.base2services.com/products/cloud-monitoring-aws/)
- [Start/Stop](https://www.base2services.com/products/start-stop-aws/)
- [Safe Test Data](https://www.base2services.com/products/safe-test-data/)
- [App Configuration](https://www.base2services.com/products/application-config/)
- [Secure Access](https://www.base2services.com/products/secure-access-aws/)
- [Ask about AWS](https://www.base2services.com/products/ai-access-aws/)
- [Resource Documenter](https://www.base2services.com/products/resource-documenter/)

### Company

- [About Us](https://www.base2services.com/about/)
- [Customers](https://www.base2services.com/customers/)
- [How We Work](https://www.base2services.com/how-we-work/)
- [Why Choose Us](https://www.base2services.com/how-we-work/why-choose-us/)
- [Explore](https://www.base2services.com/community/)
- [Blog](https://blog.base2services.com/)
- [Videos](https://www.base2services.com/community/videos/)

![ISO 27001 Certified](https://www.base2services.com/images/ISO-27001-certified_white.svg) [![JASANZ Certified](https://www.base2services.com/images/jasanz.svg)](https://register.jas-anz.org/certified-organisations)

 © base2Services | [Terms & Conditions](https://www.base2services.com/community/terms.html) | [Privacy](https://www.base2services.com/community/privacy.html)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Jared Brook",
    "url" : "https://blog.base2services.com/author/jared-brook"
  },
  "dateModified" : "2026-04-07T15:47:23.935Z",
  "datePublished" : "2026-04-07T15:42:16.000Z",
  "headline" : "Deep Health Checks Without the Risk: HMAC Signing in Guardian",
  "image" : [ "https://blog.base2services.com/hubfs/Blog%20Thumbnails/Blog%20Feature%20Update%20v1.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.base2services.com/authenticated-health-checks-without-exposure-hmac-signing-in-cfnguardian",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.base2services.com/hubfs/B2S_logo_600x400px.png"
    },
    "name" : "base2Services"
  }
}
```