mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 06:33:12 +00:00
19 lines
928 B
Terraform
19 lines
928 B
Terraform
|
|
# Secrets Manager — intentionally empty of resources.
|
||
|
|
#
|
||
|
|
# meal-order-manager/slack-bot-token is created and rotated out-of-band. Only
|
||
|
|
# its ARN enters this configuration, through var.slack_bot_secret_arn, and it is
|
||
|
|
# used for one thing: scoping secretsmanager:GetSecretValue on the slack-notifier
|
||
|
|
# and sync-roster execution roles (see iam.tf).
|
||
|
|
#
|
||
|
|
# Secret VALUES never enter Terraform state. An aws_secretsmanager_secret_version
|
||
|
|
# resource would write the plaintext into state and is never used in this repo.
|
||
|
|
# Rotate with:
|
||
|
|
# aws secretsmanager put-secret-value \
|
||
|
|
# --secret-id meal-order-manager/slack-bot-token --secret-string <value>
|
||
|
|
#
|
||
|
|
# There is no `data "aws_secretsmanager_secret_version"` lookup either: reading a
|
||
|
|
# version through a data source also lands the plaintext in state.
|
||
|
|
#
|
||
|
|
# If a future resource needs another secret, add a variable carrying its ARN —
|
||
|
|
# never a managed resource, and never a version.
|