meal-order-manager/terraform/secrets.tf

19 lines
928 B
Terraform
Raw Normal View History

# Secrets Manager — intentionally empty of resources.
#
# meal-order-manager/slack-bot-token is created and rotated out-of-band. Only
# its ARN enters this configuration, through var.slack_bot_secret_arn, and it is
# used for one thing: scoping secretsmanager:GetSecretValue on the slack-notifier
# and sync-roster execution roles (see iam.tf).
#
# Secret VALUES never enter Terraform state. An aws_secretsmanager_secret_version
# resource would write the plaintext into state and is never used in this repo.
# Rotate with:
# aws secretsmanager put-secret-value \
# --secret-id meal-order-manager/slack-bot-token --secret-string <value>
#
# There is no `data "aws_secretsmanager_secret_version"` lookup either: reading a
# version through a data source also lands the plaintext in state.
#
# If a future resource needs another secret, add a variable carrying its ARN —
# never a managed resource, and never a version.