Skip to content

Secrets Manager

Stores passwords, API keys, connection strings, and other secrets for your application. Each secret is encrypted with its own KMS key, and only services you grant access to can read it. Your ECS Fargate service or Lambda function reads each secret as an environment variable.

Byks guides

Terraform configuration

terraform-byks-module doesn't create secrets. Create them with the terraform-aws-secretsmanager-secrets module, then pass the secret ARNs to secretsmanager_secrets on an ECS service, as shown in Secrets Manager.

Each instance of the module creates one KMS key, one secret per entry in secrets, and two IAM policies that cover every secret in that instance. Each secret is named <environment>-<application_name>-<secret> and holds the placeholder value INITIAL VALUE until you set the real value in the AWS console. A service that gets the read policy can read every secret in the instance. To keep services from reading each other's secrets, create one instance per service.

secretsmanager.tf
module "secretsmanager" {
  source = "git@github.com:BYM-IKT/terraform-aws-secretsmanager-secrets.git?ref=v5"
  account_id       = var.account_id
  environment      = var.environment
  region           = var.region
  application_name = var.application_name
  secrets          = ["MY_NEW_SECRET"]
  # options go here
}

Options

Option Type Default Description
environment string required Environment name, for example test or prod. Part of every secret name, the KMS key alias, and the IAM policy names.
application_name string required Name of the application or service. Part of every secret name, the KMS key alias alias/<environment>-<application_name>, and the IAM policy names. Use a different value for each instance in the same account, because AWS requires the alias and policy names to be unique.
secrets list(string) required Short names of the secrets to create, for example ["POSTGRESQL_CONNECTION_STRING"]. Each name becomes a key in the secrets_arn and secrets_name outputs.
region string required The AWS region, for example var.region from environment.tf. The module requires this input, but the current version doesn't use the value.
account_id string required The AWS account ID, for example var.account_id. The module requires this input, but the current version doesn't use the value.
kms_key_policy_override string null A JSON key policy for the KMS key that encrypts the secrets, for example to grant another account access. With null, AWS applies its default key policy.
secretsmanager_policy_override string null A JSON resource policy attached to every secret in the instance, for example to grant another account access.
recovery_window_in_days number 7 Days AWS keeps a deleted secret before it's gone for good. Use a value from 7 to 30, or 0 to delete at once with no recovery.

Outputs

Output Description
secrets_arn Map from each short name in secrets to the secret's ARN. Pass these to secretsmanager_secrets on an ECS service.
secrets_name Map from each short name in secrets to the full secret name.
secrets_read_policy_arn ARN of the IAM policy that grants read access to every secret in the instance.
secrets_read_write_policy_arn ARN of the IAM policy that grants read and write access to every secret in the instance, as needed for secret rotation. It doesn't allow creating new secrets.
kms_id, kms_arn, kms_alias ID, ARN, and alias of the KMS key that encrypts the secrets.

The outputs secrets_read_policy and secrets_read_write_policy still exist, but they're deprecated. Use the _arn versions instead.

Resources