Secrets Manager
Stores passwords, API keys, connection strings, and other secrets for your application. Each secret is encrypted with its own KMS key, and only services you grant access to can read it. Your ECS Fargate service or Lambda function reads each secret as an environment variable.
Byks guides
-
Use a secret in your application
Create a secret, set its value, and read it from an ECS Fargate service or a Lambda function.
Terraform configuration
terraform-byks-module doesn't create secrets. Create them with the terraform-aws-secretsmanager-secrets module, then pass the secret ARNs to secretsmanager_secrets on an ECS service, as shown in Secrets Manager.
Each instance of the module creates one KMS key, one secret per entry in secrets, and two IAM policies that cover every secret in that instance. Each secret is named <environment>-<application_name>-<secret> and holds the placeholder value INITIAL VALUE until you set the real value in the AWS console. A service that gets the read policy can read every secret in the instance. To keep services from reading each other's secrets, create one instance per service.
module "secretsmanager" {
source = "git@github.com:BYM-IKT/terraform-aws-secretsmanager-secrets.git?ref=v5"
account_id = var.account_id
environment = var.environment
region = var.region
application_name = var.application_name
secrets = ["MY_NEW_SECRET"]
# options go here
}
Options
| Option | Type | Default | Description |
|---|---|---|---|
environment |
string |
required | Environment name, for example test or prod. Part of every secret name, the KMS key alias, and the IAM policy names. |
application_name |
string |
required | Name of the application or service. Part of every secret name, the KMS key alias alias/<environment>-<application_name>, and the IAM policy names. Use a different value for each instance in the same account, because AWS requires the alias and policy names to be unique. |
secrets |
list(string) |
required | Short names of the secrets to create, for example ["POSTGRESQL_CONNECTION_STRING"]. Each name becomes a key in the secrets_arn and secrets_name outputs. |
region |
string |
required | The AWS region, for example var.region from environment.tf. The module requires this input, but the current version doesn't use the value. |
account_id |
string |
required | The AWS account ID, for example var.account_id. The module requires this input, but the current version doesn't use the value. |
kms_key_policy_override |
string |
null |
A JSON key policy for the KMS key that encrypts the secrets, for example to grant another account access. With null, AWS applies its default key policy. |
secretsmanager_policy_override |
string |
null |
A JSON resource policy attached to every secret in the instance, for example to grant another account access. |
recovery_window_in_days |
number |
7 |
Days AWS keeps a deleted secret before it's gone for good. Use a value from 7 to 30, or 0 to delete at once with no recovery. |
Outputs
| Output | Description |
|---|---|
secrets_arn |
Map from each short name in secrets to the secret's ARN. Pass these to secretsmanager_secrets on an ECS service. |
secrets_name |
Map from each short name in secrets to the full secret name. |
secrets_read_policy_arn |
ARN of the IAM policy that grants read access to every secret in the instance. |
secrets_read_write_policy_arn |
ARN of the IAM policy that grants read and write access to every secret in the instance, as needed for secret rotation. It doesn't allow creating new secrets. |
kms_id, kms_arn, kms_alias |
ID, ARN, and alias of the KMS key that encrypts the secrets. |
The outputs secrets_read_policy and secrets_read_write_policy still exist, but they're deprecated. Use the _arn versions instead.
Resources
-
AWS documentation
Official AWS documentation for Secrets Manager