Skip to content

Commit 5e58b9a

Browse files
author
Ryan Jiang
authored
Set recovery window in days to 0 for secrets
1 parent 1ef8b83 commit 5e58b9a

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

modules/aws_ecs_ec2/secrets.tf

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ resource "random_string" "rds_password" {
66
resource "aws_secretsmanager_secret" "rds_password" {
77
name = "${var.deployment_name}-rds-password"
88
description = "This is the password for the Retool RDS instance"
9+
recovery_window_in_days = 0
910
}
1011

1112
resource "aws_secretsmanager_secret_version" "rds_password" {
@@ -16,6 +17,7 @@ resource "aws_secretsmanager_secret_version" "rds_password" {
1617
resource "aws_secretsmanager_secret" "rds_username" {
1718
name = "${var.deployment_name}-rds-username"
1819
description = "This is the username for the Retool RDS instance"
20+
recovery_window_in_days = 0
1921
}
2022

2123
resource "aws_secretsmanager_secret_version" "rds_username" {
@@ -31,6 +33,7 @@ resource "random_string" "jwt_secret" {
3133
resource "aws_secretsmanager_secret" "jwt_secret" {
3234
name = "${var.deployment_name}-jwt-secret"
3335
description = "This is the secret for Retool JWTs"
36+
recovery_window_in_days = 0
3437
}
3538

3639
resource "aws_secretsmanager_secret_version" "jwt_secret" {
@@ -47,6 +50,7 @@ resource "random_string" "encryption_key" {
4750
resource "aws_secretsmanager_secret" "encryption_key" {
4851
name = "${var.deployment_name}-encryption-key"
4952
description = "This is the secret for encrypting credentials"
53+
recovery_window_in_days = 0
5054
}
5155

5256
resource "aws_secretsmanager_secret_version" "encryption_key" {

0 commit comments

Comments
 (0)