sh-openswe-traces/terraform/secrets.tf
Adam Moussa 5f430d9dfd
feat(infra): convert sh-openswe-traces to HCP Terraform (#8)
Freeze SAM CD and add terraform/ for seahaven-prod with account-suffixed
buckets so HCP owns deploy before mgmt cutover. Suppress CKV_AWS_40 for
the LangSmith export IAM user with documented mitigations.
2026-08-05 18:33:03 -04:00

15 lines
888 B
HCL

# Holder only — the access key is minted out-of-band and written with
# `aws secretsmanager put-secret-value` (see README). Never manage secret
# values in Terraform so they never enter HCP state.
#
# Pre-created in seahaven-prod for PLAT-73 step 1. Import on first apply:
# terraform import aws_secretsmanager_secret.export_key \
# arn:aws:secretsmanager:us-east-1:011934824531:secret:sh-openswe/langsmith-export-s3-OQoqqU
resource "aws_secretsmanager_secret" "export_key" {
name = local.secret_name
description = "Access key for the sh-openswe-langsmith-export IAM user, consumed by LangSmith Bulk Export. Populated out-of-band post-deploy; rotate quarterly."
# Encrypted with the aws/secretsmanager managed key — deliberately NOT the
# trace CMK, so the credential and the data it protects never share a key
# the writer principal holds any KMS grant on.
}