Fix SETUP.md to use Secrets Manager, not SSM (compliance #68) (#89)

SETUP.md step 2 told operators to store the Slack token/signing secret in
SSM Parameter Store, which (a) violates the secrets-and-config handbook
(API tokens/signing values must live in Secrets Manager) and (b) contradicts
the IaC — the stack reads Secrets Manager and the IAM roles only grant
secretsmanager:GetSecretValue on afterhours-shift-manager/*, so following the
old instructions would break the deploy.

- Section 2 now uses `aws secretsmanager create-secret` for all five secrets
  (slack-bot-token, slack-signing-secret, 3cx-domain/client-id/client-secret) —
  the 3CX secrets were also previously undocumented.
- The Slack channel ID is not a secret; documented as the `ShiftChannel` deploy
  parameter (--parameter-overrides) instead of an SSM SecureString.

Addresses violation 2 of #68.
This commit is contained in:
Adam Moussa 2026-06-01 19:46:47 -04:00 • committed by GitHub
parent 26aec5dade
commit 11512f9aad
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -18,33 +18,48 @@
6. **Install to Workspace** — approve the permissions
7. Copy the **Bot User OAuth Token** (`xoxb-...`) and **Signing Secret** (under Basic Information)
## 2. Store Secrets in SSM Parameter Store
## 2. Store Secrets in AWS Secrets Manager
The stack reads these from Secrets Manager (the IAM roles grant
`secretsmanager:GetSecretValue` on `afterhours-shift-manager/*`):
```bash
aws ssm put-parameter \
--name "/afterhours-shift-manager/slack-bot-token" \
--type SecureString \
--value "xoxb-YOUR-BOT-TOKEN"
# Slack
aws secretsmanager create-secret \
--name afterhours-shift-manager/slack-bot-token \
--secret-string "xoxb-YOUR-BOT-TOKEN"
aws ssm put-parameter \
--name "/afterhours-shift-manager/slack-signing-secret" \
--type SecureString \
--value "YOUR-SIGNING-SECRET"
aws secretsmanager create-secret \
--name afterhours-shift-manager/slack-signing-secret \
--secret-string "YOUR-SIGNING-SECRET"
# Channel ID where the bot will post weekly schedules
# (right-click channel in Slack → Copy link → the ID is the last segment)
aws ssm put-parameter \
--name "/afterhours-shift-manager/channel-id" \
--type SecureString \
--value "C0XXXXXXX"
# 3CX Queue XAPI (used by roster-sync and ring-scheduler)
aws secretsmanager create-secret \
--name afterhours-shift-manager/3cx-domain \
--secret-string "yourcompany.3cx.us"
aws secretsmanager create-secret \
--name afterhours-shift-manager/3cx-client-id \
--secret-string "YOUR-3CX-CLIENT-ID"
aws secretsmanager create-secret \
--name afterhours-shift-manager/3cx-client-secret \
--secret-string "YOUR-3CX-CLIENT-SECRET"
```
> The Slack **channel ID** is not a secret — it's passed as the `ShiftChannel`
> deploy parameter in step 3, not stored in Secrets Manager or SSM.
## 3. Deploy the Stack
```bash
# Build and deploy
# Build and deploy. ShiftChannel is the Slack channel ID for schedule posts
# (right-click the channel in Slack → Copy link → the ID is the last segment).
sam build
sam deploy --guided --stack-name afterhours-shift-manager --region us-east-1
sam deploy --guided \
--stack-name afterhours-shift-manager \
--region us-east-1 \
--parameter-overrides ShiftChannel=C0XXXXXXX QueueNumber=801
# Note the SlackBotApiUrl output — you'll need it for step 4
```