mirror of
https://github.com/Sea-Haven-Industries/afterhours-shift-manager.git
synced 2026-09-30 04:33:10 +00:00
SETUP.md step 2 told operators to store the Slack token/signing secret in SSM Parameter Store, which (a) violates the secrets-and-config handbook (API tokens/signing values must live in Secrets Manager) and (b) contradicts the IaC — the stack reads Secrets Manager and the IAM roles only grant secretsmanager:GetSecretValue on afterhours-shift-manager/*, so following the old instructions would break the deploy. - Section 2 now uses `aws secretsmanager create-secret` for all five secrets (slack-bot-token, slack-signing-secret, 3cx-domain/client-id/client-secret) — the 3CX secrets were also previously undocumented. - The Slack channel ID is not a secret; documented as the `ShiftChannel` deploy parameter (--parameter-overrides) instead of an SSM SecureString. Addresses violation 2 of #68.
This commit is contained in:
parent
26aec5dade
commit
11512f9aad
1 changed files with 32 additions and 17 deletions
49
SETUP.md
49
SETUP.md
|
|
@ -18,33 +18,48 @@
|
|||
6. **Install to Workspace** — approve the permissions
|
||||
7. Copy the **Bot User OAuth Token** (`xoxb-...`) and **Signing Secret** (under Basic Information)
|
||||
|
||||
## 2. Store Secrets in SSM Parameter Store
|
||||
## 2. Store Secrets in AWS Secrets Manager
|
||||
|
||||
The stack reads these from Secrets Manager (the IAM roles grant
|
||||
`secretsmanager:GetSecretValue` on `afterhours-shift-manager/*`):
|
||||
|
||||
```bash
|
||||
aws ssm put-parameter \
|
||||
--name "/afterhours-shift-manager/slack-bot-token" \
|
||||
--type SecureString \
|
||||
--value "xoxb-YOUR-BOT-TOKEN"
|
||||
# Slack
|
||||
aws secretsmanager create-secret \
|
||||
--name afterhours-shift-manager/slack-bot-token \
|
||||
--secret-string "xoxb-YOUR-BOT-TOKEN"
|
||||
|
||||
aws ssm put-parameter \
|
||||
--name "/afterhours-shift-manager/slack-signing-secret" \
|
||||
--type SecureString \
|
||||
--value "YOUR-SIGNING-SECRET"
|
||||
aws secretsmanager create-secret \
|
||||
--name afterhours-shift-manager/slack-signing-secret \
|
||||
--secret-string "YOUR-SIGNING-SECRET"
|
||||
|
||||
# Channel ID where the bot will post weekly schedules
|
||||
# (right-click channel in Slack → Copy link → the ID is the last segment)
|
||||
aws ssm put-parameter \
|
||||
--name "/afterhours-shift-manager/channel-id" \
|
||||
--type SecureString \
|
||||
--value "C0XXXXXXX"
|
||||
# 3CX Queue XAPI (used by roster-sync and ring-scheduler)
|
||||
aws secretsmanager create-secret \
|
||||
--name afterhours-shift-manager/3cx-domain \
|
||||
--secret-string "yourcompany.3cx.us"
|
||||
|
||||
aws secretsmanager create-secret \
|
||||
--name afterhours-shift-manager/3cx-client-id \
|
||||
--secret-string "YOUR-3CX-CLIENT-ID"
|
||||
|
||||
aws secretsmanager create-secret \
|
||||
--name afterhours-shift-manager/3cx-client-secret \
|
||||
--secret-string "YOUR-3CX-CLIENT-SECRET"
|
||||
```
|
||||
|
||||
> The Slack **channel ID** is not a secret — it's passed as the `ShiftChannel`
|
||||
> deploy parameter in step 3, not stored in Secrets Manager or SSM.
|
||||
|
||||
## 3. Deploy the Stack
|
||||
|
||||
```bash
|
||||
# Build and deploy
|
||||
# Build and deploy. ShiftChannel is the Slack channel ID for schedule posts
|
||||
# (right-click the channel in Slack → Copy link → the ID is the last segment).
|
||||
sam build
|
||||
sam deploy --guided --stack-name afterhours-shift-manager --region us-east-1
|
||||
sam deploy --guided \
|
||||
--stack-name afterhours-shift-manager \
|
||||
--region us-east-1 \
|
||||
--parameter-overrides ShiftChannel=C0XXXXXXX QueueNumber=801
|
||||
|
||||
# Note the SlackBotApiUrl output — you'll need it for step 4
|
||||
```
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue