Parameter Store
Stores configuration values centrally, such as URLs to other services, so you can change them without a code change. BYM creates every parameter as an encrypted SecureString, so you can also use Parameter Store for sensitive values. Your ECS Fargate service or Lambda function reads each parameter as an environment variable.
Byks guides
-
Use a parameter in your application
Create a parameter, set its value, and read it from an ECS Fargate service or a Lambda function.
Terraform configuration
terraform-byks-module doesn't create parameters. Create them with the terraform-aws-ssm-parameters-secure module, then pass the parameter ARNs to ssm_secrets on an ECS service, as shown in Parameter Store.
Each instance of the module creates one KMS key, one encrypted SecureString parameter per entry in parameters, and one IAM policy that grants read access to every parameter in that instance. Each parameter starts with the placeholder value init. Terraform ignores later changes to the value, so you can set it in the AWS console without Terraform resetting it. To keep services from reading each other's parameters, create one instance per service.
module "ssm_parameters" {
source = "git@github.com:BYM-IKT/terraform-aws-ssm-parameters-secure.git?ref=v2"
application_name = var.application_name
environment = var.environment
parameters = ["SvarUt/BaseUrl"]
# options go here
}
Options
| Option | Type | Default | Description |
|---|---|---|---|
environment |
string |
required | Environment name, for example test or prod. Part of the parameter path prefix, the KMS key alias, and the IAM policy name. |
application_name |
string |
required | Name of the application or service. Part of the parameter path prefix, the KMS key alias alias/ssm-<environment>-<application_name>, and the IAM policy name. Use a different value for each instance in the same account, because AWS requires the alias and policy names to be unique. |
parameters |
list(string) |
required | Short names of the parameters to create, for example ["SvarUt/BaseUrl"]. Each name becomes a key in the parameters and parameters_arn outputs. |
override_parameter_prefix |
string |
null |
Path prefix to use instead of <environment>/<application_name>. Leave out the leading and trailing slash. The parameters_arn output ignores this setting and always uses the default prefix, so use the parameters output when you set it. |
Outputs
| Output | Description |
|---|---|
parameters |
Map from each short name in parameters to the full parameter name, for example /test/kattehotell/SvarUt/BaseUrl. |
parameters_arn |
Map from each short name in parameters to the parameter ARN. Pass these to ssm_secrets on an ECS service. |
parameter_read_policy |
ARN of the IAM policy that grants read access to every parameter in the instance. |
parameter_read_policy_json |
The same read policy as a JSON document, for merging into another policy. |
kms_id, kms_arn, kms_alias |
ID, ARN, and alias of the KMS key that encrypts the parameters. |
Resources
-
AWS documentation
Official AWS documentation for Parameter Store