Skip to content

Parameter Store

Stores configuration values centrally, such as URLs to other services, so you can change them without a code change. BYM creates every parameter as an encrypted SecureString, so you can also use Parameter Store for sensitive values. Your ECS Fargate service or Lambda function reads each parameter as an environment variable.

Byks guides

Terraform configuration

terraform-byks-module doesn't create parameters. Create them with the terraform-aws-ssm-parameters-secure module, then pass the parameter ARNs to ssm_secrets on an ECS service, as shown in Parameter Store.

Each instance of the module creates one KMS key, one encrypted SecureString parameter per entry in parameters, and one IAM policy that grants read access to every parameter in that instance. Each parameter starts with the placeholder value init. Terraform ignores later changes to the value, so you can set it in the AWS console without Terraform resetting it. To keep services from reading each other's parameters, create one instance per service.

ssm.tf
module "ssm_parameters" {
  source = "git@github.com:BYM-IKT/terraform-aws-ssm-parameters-secure.git?ref=v2"
  application_name = var.application_name
  environment      = var.environment
  parameters       = ["SvarUt/BaseUrl"]
  # options go here
}

Options

Option Type Default Description
environment string required Environment name, for example test or prod. Part of the parameter path prefix, the KMS key alias, and the IAM policy name.
application_name string required Name of the application or service. Part of the parameter path prefix, the KMS key alias alias/ssm-<environment>-<application_name>, and the IAM policy name. Use a different value for each instance in the same account, because AWS requires the alias and policy names to be unique.
parameters list(string) required Short names of the parameters to create, for example ["SvarUt/BaseUrl"]. Each name becomes a key in the parameters and parameters_arn outputs.
override_parameter_prefix string null Path prefix to use instead of <environment>/<application_name>. Leave out the leading and trailing slash. The parameters_arn output ignores this setting and always uses the default prefix, so use the parameters output when you set it.

Outputs

Output Description
parameters Map from each short name in parameters to the full parameter name, for example /test/kattehotell/SvarUt/BaseUrl.
parameters_arn Map from each short name in parameters to the parameter ARN. Pass these to ssm_secrets on an ECS service.
parameter_read_policy ARN of the IAM policy that grants read access to every parameter in the instance.
parameter_read_policy_json The same read policy as a JSON document, for merging into another policy.
kms_id, kms_arn, kms_alias ID, ARN, and alias of the KMS key that encrypts the parameters.

Resources