mirror of
https://github.com/Sea-Haven-Industries/sh-openswe-traces.git
synced 2026-09-30 10:23:15 +00:00
Freeze SAM CD and add terraform/ for seahaven-prod with account-suffixed buckets so HCP owns deploy before mgmt cutover. Suppress CKV_AWS_40 for the LangSmith export IAM user with documented mitigations.
15 lines
888 B
HCL
15 lines
888 B
HCL
# Holder only — the access key is minted out-of-band and written with
|
|
# `aws secretsmanager put-secret-value` (see README). Never manage secret
|
|
# values in Terraform so they never enter HCP state.
|
|
#
|
|
# Pre-created in seahaven-prod for PLAT-73 step 1. Import on first apply:
|
|
# terraform import aws_secretsmanager_secret.export_key \
|
|
# arn:aws:secretsmanager:us-east-1:011934824531:secret:sh-openswe/langsmith-export-s3-OQoqqU
|
|
resource "aws_secretsmanager_secret" "export_key" {
|
|
name = local.secret_name
|
|
description = "Access key for the sh-openswe-langsmith-export IAM user, consumed by LangSmith Bulk Export. Populated out-of-band post-deploy; rotate quarterly."
|
|
|
|
# Encrypted with the aws/secretsmanager managed key — deliberately NOT the
|
|
# trace CMK, so the credential and the data it protects never share a key
|
|
# the writer principal holds any KMS grant on.
|
|
}
|