# Holder only — the access key is minted out-of-band and written with # `aws secretsmanager put-secret-value` (see README). Never manage secret # values in Terraform so they never enter HCP state. # # Pre-created in seahaven-prod for PLAT-73 step 1. Import on first apply: # terraform import aws_secretsmanager_secret.export_key \ # arn:aws:secretsmanager:us-east-1:011934824531:secret:sh-openswe/langsmith-export-s3-OQoqqU resource "aws_secretsmanager_secret" "export_key" { name = local.secret_name description = "Access key for the sh-openswe-langsmith-export IAM user, consumed by LangSmith Bulk Export. Populated out-of-band post-deploy; rotate quarterly." # Encrypted with the aws/secretsmanager managed key — deliberately NOT the # trace CMK, so the credential and the data it protects never share a key # the writer principal holds any KMS grant on. }