Commit bfe25ea
authored
## 🎫 Ticket
BCDA-9727
## 🛠 Changes
This change set updates the sops values files for all path-to-production
environments to include both us-east-1 and us-west-2 homed KMS keys.
This also simplifies the `10-config` terraform, introduces a mechanism
for generating the distributed `sopsw` script via terraform input
variable, introduces a root-level `.terraform-docs.yaml` configuration
file for `terraform-docs`, and refreshes the included README.
## ℹ️ Context
In the unlikely event of us-east-1 availability issues in SSM and/or
KMS, we need to be able to use KMS keys homes in the BCP/GDR us-west-2
environment. This requires re-encryption of all encrypted values.
Re-encryption was accommodated by decrypting previous sopsw values files
via `sopsw -d` and re-encrypting with `sops -e` alongside appropriate
`.sops.yaml` that encoded the comma-delimited kms keys in the following
format:
```
creation_rules:
- kms: arn:aws:kms:us-east-1:${aws_account_id}:alias/bcda-${env},arn:aws:kms:us-west-2:${aws_account_id}:alias/bcda-${env}
unencrypted_regex: /nonsensitive/
mac_only_encrypted: true
stores:
yaml:
indent: 2
```
## 🧪 Validation
`tofu` invocations and the following `sopsw` commands continue to
function under `10-config` with authenticated shells:
```sh
bin/sopsw -d values/dev.sopsw.yaml
bin/sopsw -d values/test.sopsw.yaml
bin/sopsw -d values/sandbox.sopsw.yaml
bin/sopsw -d values/prod.sopsw.yaml
```
1 parent 7444e04 commit bfe25ea
File tree
8 files changed
+811
-671
lines changed- ops/services/10-config
- values
8 files changed
+811
-671
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
16 | | - | |
| 16 | + | |
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| |||
63 | 63 | | |
64 | 64 | | |
65 | 65 | | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
| 2 | + | |
4 | 3 | | |
5 | 4 | | |
6 | 5 | | |
| |||
14 | 13 | | |
15 | 14 | | |
16 | 15 | | |
17 | | - | |
| 16 | + | |
18 | 17 | | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
| 18 | + | |
| 19 | + | |
24 | 20 | | |
0 commit comments