Skip to content

Added noecho on secret parameters - #20

Open
Smiddie31 wants to merge 1 commit into
aws-samples:mainfrom
Smiddie31:addParameterMasking
Open

Smiddie31 wants to merge 1 commit into
aws-samples:mainfrom
Smiddie31:addParameterMasking

Conversation

@Smiddie31

Copy link
Copy Markdown

Description of changes:
Added 'noecho' to the teams, slack and chime webhook parameters masking them from the console.
At present these parameters are saved as secretmanager secrets, however the parameter values are visible in the cloudformation console.

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@rarylson

Copy link
Copy Markdown

My personal thoughts on this:

  • Webhooks are secrets. So the NoEcho option totally makes sense here.
  • However, the project also supports deploy via Terraform. In this case, different form CloudFormation, options are versioned as well (terraform.tfvars), which includes params like SlackWebhookURL
    • So, while the Pull Request solves the problem for CloudFormation, we still have the problem for Terraform
    • I do not have any expertise on Terraform. I'm just curious about what should be the best approach.
      • Maybe the Terraform deploy should not create the secrets in Secrets Manager, but instead instruct the user to manually create them, and pass the secrets via a param like SecretsManagerName in terraform.tfvars

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants