I am working to migration a rails app from its current PaaS to aws elastic beanstalk. Everything went well except that elastic beanstalk allows configuration to have key and value combined max 4096bytes in size. As my app has many third parties api credentials making my config way bigger than 4096bytes.
I found an excellent service in AWS for storing secret credentials called AWS System Manager Parameter Store to overcome the 4096byte limitation.
My goal is to store my credentials and then load them back in to ENV variable for my application, however I found the following problems:
How to be able to separate the config value for different env, in my case I will have a staging and a production in parameter store? Do I need to duplicate the key for each env? what is the practice of organizing those keys to be able to easily load into ENV var programmatically?
How to be able to access the parameter store en it current env accordingly? i.e when the container get deployed in production env the parameter store values in production should be loaded ENV var but not those in staging.
What are the best practices to allow ElasticBeanstalk instance to access AWS system manager parameter stores via AWS IAM?
I tried a few commands in AWS CLI to read and write locally, it works well for example something like this
aws --region=us-east-1 ssm put-parameter --name STG_DB --value client --type SecureString
aws --region=us-east-1 ssm get-parameter --name STG_DB --with-decryption --output A --query Parameter.Value
I need some standard procedures or practices that people do to solve all the above problems.
Step by step guide and example will be very useful.