Skip to content

Commit b230c29

Browse files
committed
fix: need to add in cipher context to kms encryption op
1 parent 1e09c0c commit b230c29

File tree

2 files changed

+5
-4
lines changed
  • modules

2 files changed

+5
-4
lines changed

modules/rds_enhanced_monitoring_forwarder/main.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ locals {
55
role_name = coalesce(var.role_name, var.name)
66
policy_name = coalesce(var.policy_name, var.name)
77

8-
dd_api_key = try(data.aws_secretsmanager_secret_version.datadog_api_key[0].secret_string, "")
8+
dd_api_key = try(data.aws_secretsmanager_secret_version.datadog_api_key[0].secret_string, "")
99
api_app_key = <<EOF
1010
{"api_key":"${local.dd_api_key}", "app_key":"${var.dd_app_key}"}
1111
EOF
@@ -155,4 +155,5 @@ resource "aws_kms_ciphertext" "this" {
155155

156156
key_id = data.aws_kms_key.this[0].id
157157
plaintext = var.dd_app_key != "" ? local.api_app_key : local.api_key
158+
context = { LambdaFunctionName = var.name }
158159
}

modules/vpc_flow_log_forwarder/main.tf

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ locals {
55
role_name = coalesce(var.role_name, var.name)
66
policy_name = coalesce(var.policy_name, var.name)
77

8-
dd_api_key = try(data.aws_secretsmanager_secret_version.datadog_api_key[0].secret_string, "")
8+
dd_api_key = try(data.aws_secretsmanager_secret_version.datadog_api_key[0].secret_string, "")
99
api_app_key = <<EOF
1010
{"api_key":"${local.dd_api_key}", "app_key":"${var.dd_app_key}"}
1111
EOF
@@ -166,7 +166,7 @@ data "aws_secretsmanager_secret_version" "datadog_api_key" {
166166
resource "aws_kms_ciphertext" "this" {
167167
count = var.create ? 1 : 0
168168

169-
key_id = data.aws_kms_key.this[0].id
170-
169+
key_id = data.aws_kms_key.this[0].id
171170
plaintext = var.dd_app_key != "" ? local.api_app_key : local.api_key
171+
context = { LambdaFunctionName = var.name }
172172
}

0 commit comments

Comments
 (0)