Use secret names instead of partial ARNs and fix README paths

This commit is contained in:
Adam Moussa 2026-05-11 14:10:45 -04:00
parent b0e047e5a6
commit 23235cfd76
3 changed files with 8 additions and 8 deletions

View file

@ -88,5 +88,5 @@ Check Front > Company Settings > Teammates > pick a user > Custom Fields to conf
## Maintenance ## Maintenance
- **New teammates:** Automatically picked up if they exist in both Google Workspace and Front with the same email. - **New teammates:** Automatically picked up if they exist in both Google Workspace and Front with the same email.
- **Schedule changes:** Update the EventBridge rule in `cdk/lib/google-user-sync-stack.js`. - **Schedule changes:** Update the EventBridge rule in `lib/google-user-sync-stack.js`.
- **Additional fields:** Add as custom fields in Front, then update the field mapping in `lambda/index.js` (`buildCustomFields()`). - **Additional fields:** Add as custom fields in Front, then update the field mapping in `lambda/index.js`.

View file

@ -5,8 +5,8 @@
* and syncs job title + phone to Front teammate custom fields. * and syncs job title + phone to Front teammate custom fields.
* *
* Environment variables: * Environment variables:
* GOOGLE_SECRET_ARN - Secrets Manager ARN for Google service account JSON key * GOOGLE_SECRET_NAME - Secrets Manager name for Google service account JSON key
* FRONT_SECRET_ARN - Secrets Manager ARN for Front API token * FRONT_SECRET_NAME - Secrets Manager name for Front API token
* GOOGLE_ADMIN_EMAIL - Email of a Google Workspace admin to impersonate * GOOGLE_ADMIN_EMAIL - Email of a Google Workspace admin to impersonate
* GOOGLE_DOMAIN - Domain to list users for (e.g. seahaven.com) * GOOGLE_DOMAIN - Domain to list users for (e.g. seahaven.com)
* GOOGLE_OUS - Comma-separated org unit paths to sync (e.g. /Office/Scheduling,/Office/Operations) * GOOGLE_OUS - Comma-separated org unit paths to sync (e.g. /Office/Scheduling,/Office/Operations)
@ -196,10 +196,10 @@ exports.handler = async (event) => {
// 1. Fetch secrets // 1. Fetch secrets
const [googleSecretRes, frontSecretRes] = await Promise.all([ const [googleSecretRes, frontSecretRes] = await Promise.all([
sm.send( sm.send(
new GetSecretValueCommand({ SecretId: process.env.GOOGLE_SECRET_ARN }) new GetSecretValueCommand({ SecretId: process.env.GOOGLE_SECRET_NAME })
), ),
sm.send( sm.send(
new GetSecretValueCommand({ SecretId: process.env.FRONT_SECRET_ARN }) new GetSecretValueCommand({ SecretId: process.env.FRONT_SECRET_NAME })
), ),
]); ]);

View file

@ -37,8 +37,8 @@ class GoogleUserSyncStack extends Stack {
timeout: Duration.minutes(5), timeout: Duration.minutes(5),
memorySize: 256, memorySize: 256,
environment: { environment: {
GOOGLE_SECRET_ARN: googleSecret.secretArn, GOOGLE_SECRET_NAME: "google-user-sync/google-service-account",
FRONT_SECRET_ARN: frontSecret.secretArn, FRONT_SECRET_NAME: "google-user-sync/front-api-token",
GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com", GOOGLE_ADMIN_EMAIL: "adam@seahavenind.com",
GOOGLE_DOMAIN: "seahavenind.com", GOOGLE_DOMAIN: "seahavenind.com",
GOOGLE_OUS: "/Office/Scheduling,/Office/Operations", GOOGLE_OUS: "/Office/Scheduling,/Office/Operations",