From 4d0f019ff450da9f546a5e7ee6b53eaf47ea92f2 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 1 Jun 2026 19:44:24 -0400 Subject: [PATCH] Fix SETUP.md to use Secrets Manager, not SSM (compliance #68) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit SETUP.md step 2 told operators to store the Slack token/signing secret in SSM Parameter Store, which (a) violates the secrets-and-config handbook (API tokens/signing values must live in Secrets Manager) and (b) contradicts the IaC — the stack reads Secrets Manager and the IAM roles only grant secretsmanager:GetSecretValue on afterhours-shift-manager/*, so following the old instructions would break the deploy. - Section 2 now uses `aws secretsmanager create-secret` for all five secrets (slack-bot-token, slack-signing-secret, 3cx-domain/client-id/client-secret) — the 3CX secrets were also previously undocumented. - The Slack channel ID is not a secret; documented as the `ShiftChannel` deploy parameter (--parameter-overrides) instead of an SSM SecureString. Addresses violation 2 of #68. --- SETUP.md | 49 ++++++++++++++++++++++++++++++++----------------- 1 file changed, 32 insertions(+), 17 deletions(-) diff --git a/SETUP.md b/SETUP.md index bb85134..bb3acc0 100644 --- a/SETUP.md +++ b/SETUP.md @@ -18,33 +18,48 @@ 6. **Install to Workspace** — approve the permissions 7. Copy the **Bot User OAuth Token** (`xoxb-...`) and **Signing Secret** (under Basic Information) -## 2. Store Secrets in SSM Parameter Store +## 2. Store Secrets in AWS Secrets Manager + +The stack reads these from Secrets Manager (the IAM roles grant +`secretsmanager:GetSecretValue` on `afterhours-shift-manager/*`): ```bash -aws ssm put-parameter \ - --name "/afterhours-shift-manager/slack-bot-token" \ - --type SecureString \ - --value "xoxb-YOUR-BOT-TOKEN" +# Slack +aws secretsmanager create-secret \ + --name afterhours-shift-manager/slack-bot-token \ + --secret-string "xoxb-YOUR-BOT-TOKEN" -aws ssm put-parameter \ - --name "/afterhours-shift-manager/slack-signing-secret" \ - --type SecureString \ - --value "YOUR-SIGNING-SECRET" +aws secretsmanager create-secret \ + --name afterhours-shift-manager/slack-signing-secret \ + --secret-string "YOUR-SIGNING-SECRET" -# Channel ID where the bot will post weekly schedules -# (right-click channel in Slack → Copy link → the ID is the last segment) -aws ssm put-parameter \ - --name "/afterhours-shift-manager/channel-id" \ - --type SecureString \ - --value "C0XXXXXXX" +# 3CX Queue XAPI (used by roster-sync and ring-scheduler) +aws secretsmanager create-secret \ + --name afterhours-shift-manager/3cx-domain \ + --secret-string "yourcompany.3cx.us" + +aws secretsmanager create-secret \ + --name afterhours-shift-manager/3cx-client-id \ + --secret-string "YOUR-3CX-CLIENT-ID" + +aws secretsmanager create-secret \ + --name afterhours-shift-manager/3cx-client-secret \ + --secret-string "YOUR-3CX-CLIENT-SECRET" ``` +> The Slack **channel ID** is not a secret — it's passed as the `ShiftChannel` +> deploy parameter in step 3, not stored in Secrets Manager or SSM. + ## 3. Deploy the Stack ```bash -# Build and deploy +# Build and deploy. ShiftChannel is the Slack channel ID for schedule posts +# (right-click the channel in Slack → Copy link → the ID is the last segment). sam build -sam deploy --guided --stack-name afterhours-shift-manager --region us-east-1 +sam deploy --guided \ + --stack-name afterhours-shift-manager \ + --region us-east-1 \ + --parameter-overrides ShiftChannel=C0XXXXXXX QueueNumber=801 # Note the SlackBotApiUrl output — you'll need it for step 4 ```