-
Notifications
You must be signed in to change notification settings - Fork 3
/
Copy pathmain.tf
36 lines (30 loc) · 923 Bytes
/
main.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
locals {
arn_map = { for k in keys(var.map) : k => aws_ssm_parameter.secret_var[k].arn }
ecs_secrets = [
for k, v in local.arn_map : {
name = k,
valueFrom = v,
}
]
}
resource "aws_kms_key" "encryption_key" {
description = "This key is used to encrypt SSM '${var.ssm_key_prefix}' parameters"
deletion_window_in_days = var.deletion_window
}
resource "aws_kms_alias" "encryption_key_alias" {
count = var.create_kms_alias ? 1 : 0
name = "alias/${var.ssm_key_prefix}"
target_key_id = aws_kms_key.encryption_key.key_id
}
moved {
from = aws_kms_alias.encryption_key_alias
to = aws_kms_alias.encryption_key_alias[0]
}
resource "aws_ssm_parameter" "secret_var" {
for_each = var.map
name = "/${var.ssm_key_prefix}/${each.key}"
type = "SecureString"
key_id = aws_kms_key.encryption_key.arn
value = each.value
tier = var.ssm_parameter_tier
}