Merge pull request #36 from Sea-Haven-Industries/feature/INFRA-5-readme-secrets-manager
Some checks are pending
Deploy / deploy (push) Waiting to run

[INFRA-5] Update README for Secrets Manager migration
This commit is contained in:
Adam Moussa 2026-06-02 20:41:46 -04:00 • committed by GitHub
commit c8a55060a9
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -62,22 +62,17 @@ Two separate CashPro APIs are used, each with its own OAuth credentials:
- Production: `https://api.bofa.com` - Production: `https://api.bofa.com`
- Sandbox: `https://api-sb.bofa.com` - Sandbox: `https://api-sb.bofa.com`
## SSM Parameters ## Secrets
All BoA credentials and config are stored in AWS SSM Parameter Store (SecureString): All BoA and Slack credentials are stored in AWS Secrets Manager (per `engineering-handbook/secrets-and-config.md`). The Slack token is a plaintext secret; the two BoA secrets are JSON grouping each API's credentials:
| Parameter | Description | | Secret | Type | Contents |
|-----------|-------------| |--------|------|----------|
| `/payments-dashboard/boa-check-mgmt-app-id` | Check Management application ID | | `payments-dashboard/slack-bot-token` | plaintext | Slack Bot OAuth token (used by `processPayrollEmail`, `slackAppHome`) |
| `/payments-dashboard/boa-check-mgmt-client-id` | Check Management client ID | | `payments-dashboard/boa-check-mgmt` | JSON | `appId`, `clientId`, `token`, `accountNumber`, `companyId` — Check Management API (`processPaymentCsv`) |
| `/payments-dashboard/boa-check-mgmt-token` | Check Management client secret | | `payments-dashboard/boa-reporting` | JSON | `appId`, `clientId`, `token`, `accountNumber`, `bankId` — Reporting API (`fetchBoaTransactions`) |
| `/payments-dashboard/boa-reporting-app-id` | Reporting application ID |
| `/payments-dashboard/boa-account-info-client-id` | Reporting client ID | `boa-account-number` is duplicated into both BoA secrets. Each Lambda is granted `secretsmanager:GetSecretValue` scoped to only the secret it needs. The Expense Approval Bot uses two additional secrets (`payments-dashboard/expense-slack-token`, `payments-dashboard/expense-slack-signing-secret`).
| `/payments-dashboard/boa-account-info-token` | Reporting client secret |
| `/payments-dashboard/boa-account-number` | BoA account number |
| `/payments-dashboard/boa-company-id` | CashPro company ID (check management) |
| `/payments-dashboard/boa-bank-id` | BoA routing number |
| `/payments-dashboard/slack-bot-token` | Slack Bot OAuth token |
## Scripts ## Scripts
@ -94,4 +89,4 @@ sam build
sam deploy --guided sam deploy --guided
``` ```
The `BOA_BASE_URL` environment variable in `template.yaml` controls whether Lambdas hit production (`https://api.bofa.com`) or sandbox (`https://api-sb.bofa.com`). All other BoA config is read from SSM at runtime. The `BOA_BASE_URL` environment variable in `template.yaml` controls whether Lambdas hit production (`https://api.bofa.com`) or sandbox (`https://api-sb.bofa.com`). All other BoA config is read from Secrets Manager at runtime.