Terraform aws_iam_access_key secret in another division (using remote_state)

Viewed 352

I have a Terraform infrastructure that is divided into "parts" that looks something like this.

.
├── network
│   ├── locals.tf
│   ├── main.tf
│   ├── outputs.tf
│   └── variables.tf
├── ecs
│   ├── locals.tf
│   ├── main.tf
│   ├── outputs.tf
│   └── variables.tf
└── sqs
    ├── locals.tf
    ├── main.tf
    ├── output.tf
    └── variables.tf

In SQS, I'm creating a programmatic user with aws_iam_user and aws_iam_access_key.

resource "aws_iam_user" "sqs_write" {
  name = "sqs-queue-name-read"
  path = "/system/"
}

resource "aws_iam_access_key" "sqs_write" {
  user    = aws_iam_user.sqs_write.name
  pgp_key = local.settings.gpg_public_key
}

Now I need to be able to use aws_iam_access_key.sqs_write.secret in my ECS division.

I tried sending the secret to an "output" and use it with data.terraform_remote_state in my ECS division but Terraform says the output does not exist (most likely because it is marked as sensitive = true.

I tried to save the aws_iam_access_key.sqs_write.secret to a SSM parameter with:

resource "aws_ssm_parameter" "write_secret" {
  name        = "sqs-queue-name-write-secret-access-key"
  description = "SQS write secret access key"
  key_id      = "aws/secretsmanager"
  type        = "String"
  value       = aws_iam_access_key.sqs_write.secret
  overwrite   = true
}

But I get this error:

╷
│ Error: Missing required argument
│
│   with aws_ssm_parameter.write_secret,
│   on main.tf line 109, in resource "aws_ssm_parameter" "write_secret":
│  109:   value       = aws_iam_access_key.sqs_write.secret
│
│ The argument "value" is required, but no definition was found.
╵

So I can't seem to find a way to use the "secret" value outside of my SQS division. I could use the "encrypted_secret" version of it that works fine, but I don't know how I could decrypt it directly from Terraform so I guess it is not an option.

Any thoughts?

My version is:

Terraform v1.0.2 on linux_amd64

  • provider registry.terraform.io/hashicorp/aws v3.52.0
  • provider registry.terraform.io/hashicorp/http v2.1.0
0 Answers
Related