Fix conventions check false-positive on Secrets Manager env var names

The SAM template secret check grepped the 5 lines after `Environment:` for
API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK. That flags env var *names* like
`SLACK_BOT_TOKEN_SECRET: my-app/slack-token`, whose value is a Secrets
Manager id — i.e. the recommended pattern — so any well-architected
template failed CI.

Match on the value's shape instead: known inline secret formats (Slack
xox* tokens, AWS AKIA keys, GitHub gh*_/PAT tokens, sk- keys, PEM private
keys). Secrets Manager references and intrinsic functions no longer trip
it, while pasted real secrets still fail the build.
This commit is contained in:
Adam Moussa 2026-06-01 18:57:39 -04:00
parent f5e93b7933
commit b4922d9a78

View file

@ -125,11 +125,14 @@ jobs:
warn "SAM template: Lambda found but no explicit log retention"
fi
fi
# Check for secrets in environment variables
if grep -qiE '(API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK)' "$TEMPLATE" 2>/dev/null; then
if grep -A5 'Environment:' "$TEMPLATE" | grep -qiE '(API_KEY|SECRET|TOKEN|PASSWORD|WEBHOOK)' 2>/dev/null; then
fail "SAM template: possible secret in Lambda environment variables — use Secrets Manager"
fi
# Flag HARDCODED secret values in the template. Secrets Manager
# references (e.g. SLACK_BOT_TOKEN_SECRET: my-app/slack-token) and
# intrinsic functions (!Ref/!Sub/{{resolve:...}}) are the correct
# pattern, so match on the value's shape — not the key name, which
# legitimately contains words like TOKEN/SECRET when pointing at a
# Secrets Manager id.
if grep -qiE '(xox[abprs]-[A-Za-z0-9-]{10,}|AKIA[0-9A-Z]{16}|gh[posu]_[A-Za-z0-9]{20,}|github_pat_[A-Za-z0-9_]{20,}|sk-[A-Za-z0-9]{20,}|-----BEGIN[[:space:]][A-Z ]*PRIVATE KEY-----)' "$TEMPLATE" 2>/dev/null; then
fail "SAM template: hardcoded secret in template — use Secrets Manager"
fi
fi