Use secret names instead of partial ARNs and fix README paths

This commit is contained in:
Adam Moussa 2026-05-11 14:10:45 -04:00
parent b0e047e5a6
commit 23235cfd76
3 changed files with 8 additions and 8 deletions

View file

@ -88,5 +88,5 @@ Check Front > Company Settings > Teammates > pick a user > Custom Fields to conf
## Maintenance
- **New teammates:** Automatically picked up if they exist in both Google Workspace and Front with the same email.
- **Schedule changes:** Update the EventBridge rule in `cdk/lib/google-user-sync-stack.js`.
- **Additional fields:** Add as custom fields in Front, then update the field mapping in `lambda/index.js` (`buildCustomFields()`).
- **Schedule changes:** Update the EventBridge rule in `lib/google-user-sync-stack.js`.
- **Additional fields:** Add as custom fields in Front, then update the field mapping in `lambda/index.js`.

View file

@ -5,8 +5,8 @@
* and syncs job title + phone to Front teammate custom fields.
*
* Environment variables:
* GOOGLE_SECRET_ARN - Secrets Manager ARN for Google service account JSON key
* FRONT_SECRET_ARN - Secrets Manager ARN for Front API token
* GOOGLE_SECRET_NAME - Secrets Manager name for Google service account JSON key
* FRONT_SECRET_NAME - Secrets Manager name for Front API token
* GOOGLE_ADMIN_EMAIL - Email of a Google Workspace admin to impersonate
* GOOGLE_DOMAIN - Domain to list users for (e.g. seahaven.com)
* GOOGLE_OUS - Comma-separated org unit paths to sync (e.g. /Office/Scheduling,/Office/Operations)
@ -196,10 +196,10 @@ exports.handler = async (event) => {
// 1. Fetch secrets
const [googleSecretRes, frontSecretRes] = await Promise.all([
sm.send(
new GetSecretValueCommand({ SecretId: process.env.GOOGLE_SECRET_ARN })
new GetSecretValueCommand({ SecretId: process.env.GOOGLE_SECRET_NAME })
),
sm.send(
new GetSecretValueCommand({ SecretId: process.env.FRONT_SECRET_ARN })
new GetSecretValueCommand({ SecretId: process.env.FRONT_SECRET_NAME })
),
]);

View file

@ -37,8 +37,8 @@ class GoogleUserSyncStack extends Stack {
timeout: Duration.minutes(5),
memorySize: 256,
environment: {
GOOGLE_SECRET_ARN: googleSecret.secretArn,
FRONT_SECRET_ARN: frontSecret.secretArn,
GOOGLE_SECRET_NAME: "google-user-sync/google-service-account",
FRONT_SECRET_NAME: "google-user-sync/front-api-token",
GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com",
GOOGLE_DOMAIN: "seahavenind.com",
GOOGLE_OUS: "/Office/Scheduling,/Office/Operations",