mirror of
https://github.com/Sea-Haven-Industries/meal-order-manager.git
synced 2026-09-30 19:23:13 +00:00
Freeze SAM CD and add greenfield Terraform for seahaven-prod so HCP is the sole stack deploy path.
18 lines
928 B
HCL
18 lines
928 B
HCL
# Secrets Manager — intentionally empty of resources.
|
|
#
|
|
# meal-order-manager/slack-bot-token is created and rotated out-of-band. Only
|
|
# its ARN enters this configuration, through var.slack_bot_secret_arn, and it is
|
|
# used for one thing: scoping secretsmanager:GetSecretValue on the slack-notifier
|
|
# and sync-roster execution roles (see iam.tf).
|
|
#
|
|
# Secret VALUES never enter Terraform state. An aws_secretsmanager_secret_version
|
|
# resource would write the plaintext into state and is never used in this repo.
|
|
# Rotate with:
|
|
# aws secretsmanager put-secret-value \
|
|
# --secret-id meal-order-manager/slack-bot-token --secret-string <value>
|
|
#
|
|
# There is no `data "aws_secretsmanager_secret_version"` lookup either: reading a
|
|
# version through a data source also lands the plaintext in state.
|
|
#
|
|
# If a future resource needs another secret, add a variable carrying its ARN —
|
|
# never a managed resource, and never a version.
|