Skip to content

Commit ce8037f

Browse files
committed
Debugging the deployment for cross account secrets
1 parent 5c969fd commit ce8037f

File tree

2 files changed

+32
-6
lines changed

2 files changed

+32
-6
lines changed

cicd/cloudformation/secrets.yaml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -456,6 +456,7 @@ Resources:
456456
Properties:
457457
Name: TestRegion
458458
SecretString: !Select [1, !Split [".", !Ref SCIMEndpointUrl]]
459+
KmsKeyId: !Ref KeyAlias
459460

460461
SecretRegionPolicy:
461462
Type: AWS::SecretsManager::ResourcePolicy
@@ -488,6 +489,7 @@ Resources:
488489
Properties:
489490
Name: TestIdentityStoreId
490491
SecretString: !Ref IdentityStoreId
492+
KmsKeyId: !Ref KeyAlias
491493

492494
SecretIdentityStoreIDPolicy:
493495
Type: AWS::SecretsManager::ResourcePolicy

cicd/staging/build/stack.yml

Lines changed: 30 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -41,12 +41,36 @@ Resources:
4141
SemanticVersion: !Ref AppVersion
4242
Parameters:
4343
FunctionName: SSOSyncFunction
44-
GoogleAdminEmail: !Sub '{{resolve:secretsmanager:${GoogleAdminEmailArn}}}'
45-
GoogleCredentials: '{{resolve:secretsmanager:${GoogleCredentials}}}'
46-
SCIMEndpointUrl: '{{resolve:secretsmanager:$SCIMEndpointUrlArn}}}'
47-
SCIMEndpointAccessToken: '{{resolve:secretsmanager:${SCIMAccessTokenArn}}}'
48-
Region: '{{resolve:secretsmanager:${RegioArn}n}}'
49-
IdentityStoreID: '{{resolve:secretsmanager:${IdentityStoreIdArn}}}'
44+
GoogleAdminEmail: !Join
45+
- ''
46+
- - '{{resolve:secretsmanager:'
47+
- !Ref GoogleAdminEmailArn
48+
- '}}'
49+
GoogleCredentials: !Join
50+
- ''
51+
- - '{{resolve:secretsmanager:'
52+
- !Ref GoogleCredentialsArn
53+
- '}}'
54+
SCIMEndpointUrl: !Join
55+
- ''
56+
- - '{{resolve:secretsmanager:'
57+
- !Ref SCIMEndpointUrlArn
58+
- '}}'
59+
SCIMEndpointAccessToken: !Join
60+
- ''
61+
- - '{{resolve:secretsmanager:'
62+
- !Ref SCIMAccessTokenArn
63+
- '}}'
64+
Region: !Join
65+
- ''
66+
- - '{{resolve:secretsmanager:'
67+
- !Ref RegionArn
68+
- '}}'
69+
IdentityStoreID: !Join
70+
- ''
71+
- - '{{resolve:secretsmanager:'
72+
- !Ref IdentityStoreIdArn
73+
- '}}'
5074
SyncMethod: groups
5175
GoogleGroupMatch: !Ref GroupMatch
5276
LogLevel: warn

0 commit comments

Comments
 (0)