bastelfreak
02/22/2023, 4:32 PMIan CB
02/22/2023, 4:32 PMMartyn Smith
02/22/2023, 4:42 PMMartyn Smith
02/22/2023, 4:43 PMSlackbot
02/22/2023, 4:46 PMMartyn Smith
02/22/2023, 4:48 PM- name: "environment secrets in secretsmanager"
lookup_key: hiera_aws_sm
options:
continue_if_not_found: true
aws_access_key: <redacted>
aws_secret_key: <redacted>
assume_role: true
rolename_to_assume: AutomationAdminExecutionRole
key_replacement_token: '-'
confine_to_keys:
- 'aws_sm[a-zA-z0-9-/_+=.@!:]*'
- '[a-zA-z0-9-/_+=.@!:]*pass[a-zA-z0-9-/_+=.@!:]*'
- '[a-zA-z0-9-/_+=.@!:]*user[a-zA-z0-9-/_+=.@!:]*'
- '[a-zA-z0-9-/_+=.@!:]*cert[a-zA-z0-9-/_+=.@!:]*'
- '[a-zA-z0-9-/_+=.@!:]*key[a-zA-z0-9-/_+=.@!:]*'
accountid_to_assume: "%{facts.ec2_tags.accountid}"
region: "%{facts.ec2_metadata.placement.region}"
Is there any way to encrypt those with hiera_eyaml even though they are config for a different plugin?
Thanks
MartynSlackbot
02/22/2023, 5:53 PMnatemccurdy
02/22/2023, 6:40 PMfile() function, your file resource should use the content parameter, not the source parameter.
e.g.
file { 'C:/ssh_test/gitlab':
ensure => file,
content => file('/var/tmp/gitlab'),
}Slackbot
02/23/2023, 5:54 AMYury Bushmelev
02/23/2023, 6:36 AMYury Bushmelev
02/23/2023, 6:39 AMbastelfreak
02/23/2023, 7:06 AMOwen Beckles
02/23/2023, 8:59 AMSlackbot
02/23/2023, 9:55 AMCraig Gumbley
02/23/2023, 10:44 AMChughesvf
02/23/2023, 3:14 PMSlackbot
02/23/2023, 4:29 PMLes Shiner
02/23/2023, 4:29 PMYury Bushmelev
02/23/2023, 4:39 PMIan CB
02/23/2023, 4:41 PMramindk
02/23/2023, 4:43 PMYury Bushmelev
02/23/2023, 4:46 PMalias instead of lookupSlackbot
02/23/2023, 4:57 PMnatemccurdy
02/23/2023, 4:57 PMlookup() (the Hiera interpolation function) converts everything to a String.
alias() (the Hiera interpolation function) looks up and retains the data type of the thing that was looked up.Slackbot
02/23/2023, 5:25 PMramnad
02/23/2023, 6:11 PMSlackbot
02/23/2023, 6:14 PMDr Bunsen Honeydew
02/23/2023, 6:45 PMSlackbot
02/23/2023, 9:03 PMBrian Schonecker
02/23/2023, 9:04 PM