# Secrets Manager — intentionally empty of resources. # # meal-order-manager/slack-bot-token is created and rotated out-of-band. Only # its ARN enters this configuration, through var.slack_bot_secret_arn, and it is # used for one thing: scoping secretsmanager:GetSecretValue on the slack-notifier # and sync-roster execution roles (see iam.tf). # # Secret VALUES never enter Terraform state. An aws_secretsmanager_secret_version # resource would write the plaintext into state and is never used in this repo. # Rotate with: # aws secretsmanager put-secret-value \ # --secret-id meal-order-manager/slack-bot-token --secret-string # # There is no `data "aws_secretsmanager_secret_version"` lookup either: reading a # version through a data source also lands the plaintext in state. # # If a future resource needs another secret, add a variable carrying its ARN — # never a managed resource, and never a version.