Skip to content

Add SSM parameter for the user-bot Slack token - #213

Merged
ale210 merged 1 commit into
mainfrom
212-user-bot-slack-terraform
Oct 4, 2026
Merged

ale210 merged 1 commit into
mainfrom
212-user-bot-slack-terraform

Conversation

@ale210

@ale210 ale210 commented Oct 4, 2026

Copy link
Copy Markdown
Member

Part of #212 (PR 1 of 2: Terraform; the Lambda change follows in PR 2)

What changes did you make?

  • New SSM SecureString /user-bot/slack-bot-token (us-east-1, prevent_destroy), created from a placeholder through the write-only value_wo. The real Slack token is set by hand after merge, so it never appears in git or Terraform state
  • user-bot execution role: ssm:GetParameter on that one parameter
  • user-bot function: SLACK_TOKEN_PARAMETER environment variable holding the parameter's name, not the token
  • terraform/README.md regenerated

Why did you make the changes (we will use this info to test)?

  • So the user-bot Lambda can read a Slack bot token and send real DMs (see Wire the user-bot Lambda to Slack: bot token in SSM, real DMs, end-to-end test #212)
  • Expected plan: 1 to add, 2 to change, 0 to destroy. The parameter's value should show as (write-only attribute); the function's only change should be the environment block
  • Safe to merge before the token exists: the deployed code ignores the new variable until PR 2

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Terraform plan in terraform
With backend config files: terraform/prod.backend.tfvars
With variables: iam_only = false

Plan: 1 to add, 2 to change, 0 to destroy.
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+   create
!~  update in-place

Terraform will perform the following actions:

  # aws_iam_role_policy.user_bot will be updated in-place
!~  resource "aws_iam_role_policy" "user_bot" {
        id          = "user-bot:user-bot"
        name        = "user-bot"
!~      policy      = jsonencode(
            {
-               Statement = [
-                   {
-                       Action   = "iam:ListUserTags"
-                       Effect   = "Allow"
-                       Resource = "arn:aws:iam::035866691871:user/*"
-                       Sid      = "ReadUserTags"
                    },
-                   {
-                       Action    = "iam:UpdateLoginProfile"
-                       Condition = {
-                           StringEquals = {
-                               "iam:ResourceTag/managed-by" = "terraform-devops-security"
                            }
                        }
-                       Effect    = "Allow"
-                       Resource  = "arn:aws:iam::035866691871:user/*"
-                       Sid       = "ResetPasswordOfDevopsSecurityUsersOnly"
                    },
-                   {
-                       Action   = [
-                           "logs:CreateLogStream",
-                           "logs:PutLogEvents",
                        ]
-                       Effect   = "Allow"
-                       Resource = "arn:aws:logs:us-east-1:035866691871:log-group:/aws/lambda/user-bot:*"
-                       Sid      = "WriteOwnLogs"
                    },
                ]
-               Version   = "2012-10-17"
            }
        ) -> (known after apply)
#        (2 unchanged attributes hidden)
    }

  # aws_lambda_function.user_bot will be updated in-place
!~  resource "aws_lambda_function" "user_bot" {
        id                             = "user-bot"
        tags                           = {}
#        (32 unchanged attributes hidden)

+       environment {
+           variables = {
+               "SLACK_TOKEN_PARAMETER" = "*************************"
            }
        }

#        (3 unchanged blocks hidden)
    }

  # aws_ssm_parameter.user_bot_slack_token will be created
+   resource "aws_ssm_parameter" "user_bot_slack_token" {
+       arn              = (known after apply)
+       data_type        = (known after apply)
+       description      = "Slack bot token for the user-bot Lambda. Set by hand; see lambda/user-bot/README.md in hackforla/devops-security."
+       has_value_wo     = (known after apply)
+       id               = (known after apply)
+       insecure_value   = (known after apply)
+       key_id           = (known after apply)
+       name             = "/user-bot/slack-bot-token"
+       region           = "us-east-1"
+       tags_all         = {
+           "managed-by" = "terraform-devops-security"
        }
+       tier             = (known after apply)
+       type             = "SecureString"
+       value            = (sensitive value)
+       value_wo         = (write-only attribute)
+       value_wo_version = 1
+       version          = (known after apply)
    }

Plan: 1 to add, 2 to change, 0 to destroy.

✅ Plan applied in Apply Terraform changes on merge #51

@ale210
ale210 merged commit 1c93e6f into main Oct 4, 2026
2 checks passed
@ale210
ale210 deleted the 212-user-bot-slack-terraform branch October 4, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant