generated from terraform-ibm-modules/terraform-ibm-module-template
    
        
        - 
                Notifications
    You must be signed in to change notification settings 
- Fork 3
KMS refactor and clean up #363
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
          
     Merged
      
      
    
                
     Merged
            
            
          Conversation
  
    
      This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
      Learn more about bidirectional Unicode characters
    
  
  
    
    | /run pipeline | 
| /run pipeline | 
| /run pipeline | 
| /run pipeline | 
  This was referenced Dec 11, 2024 
      
              
                    jor2
  
              
              approved these changes
              
                  
                    Dec 11, 2024 
                  
              
              
            
            
| Looks good. Now lets try use the same approach in other ICD modules. | 
| 🎉 This PR is included in version 1.25.0 🎉 The release is available on: 
 Your semantic-release bot 📦🚀 | 
  This was referenced Dec 11, 2024 
      
  
    Sign up for free
    to join this conversation on GitHub.
    Already have an account?
    Sign in to comment
  
      
  Add this suggestion to a batch that can be applied as a single commit.
  This suggestion is invalid because no changes were made to the code.
  Suggestions cannot be applied while the pull request is closed.
  Suggestions cannot be applied while viewing a subset of changes.
  Only one suggestion per line can be applied in a batch.
  Add this suggestion to a batch that can be applied as a single commit.
  Applying suggestions on deleted lines is not supported.
  You must change the existing code in this line in order to create a valid suggestion.
  Outdated suggestions cannot be applied.
  This suggestion has been applied or marked resolved.
  Suggestions cannot be applied from pending reviews.
  Suggestions cannot be applied on multi-line comments.
  Suggestions cannot be applied while the pull request is queued to merge.
  Suggestion cannot be applied right now. Please check back later.
  
    
  
    
Description
(NOTE: upgrade test had to be skipped because the main branch code fail due to this bug)
Root module:
existing_kms_instance_guidand updated the code to parse the GUID from the KMS key CRNbackup_encryption_key_crnas the regex in main branch would not of accepted eu-es for example, which is supported for HPCS. I no longer check for region in the regex so we don't have to maintain it when new regions support is added in the future.use_same_kms_key_for_backups(which will fix the problem that we saw in https://github.ibm.com/GoldenEye/issues/issues/11876)kms_encryption_enabledtouse_ibm_owned_encryption_keyso we are consistent with the fscloud and DA.crn-parsersubmoduleFSCloud updates:
use_default_backup_encryption_keyinputbackup_encryption_key_crninputuse_same_kms_key_for_backupsinputkms_key_crninputDA updates:
use_default_backup_encryption_keyexisting_backup_kms_instance_crnand removed support for creating a backup key. It gets too complicated then as we would need to expose the ability to use existing key rings etc. If user really wants to use a different key for backups (which seems to be an edge use case), they can useexisting_backup_kms_key_crnand use an existing key.skip_iam_authorization_policyhas been renamedskip_es_kms_auth_policysince the DA also supports creating secrets manager auth policycrn-parsersubmoduleRelease required?
x.x.X)x.X.x)X.x.x)Release notes content
Run the pipeline
If the CI pipeline doesn't run when you create the PR, the PR requires a user with GitHub collaborators access to run the pipeline.
Run the CI pipeline when the PR is ready for review and you expect tests to pass. Add a comment to the PR with the following text:
Checklist for reviewers
For mergers