Don't use parameters to pass secrets to GCP or AWS (#2039)

* Don't use parameters to pass secrets to GCP or AWS

Signed-off-by: Spike Curtis <spike@coder.com>

* Fix fmt

Signed-off-by: Spike Curtis <spike@coder.com>
This commit is contained in:
Spike Curtis
2022-06-03 14:29:22 -07:00
committed by GitHub
parent 43f622a52d
commit 847e2b18da
11 changed files with 180 additions and 96 deletions
+7
View File
@@ -10,6 +10,13 @@ tags: [cloud, aws]
Pick this template in `coder templates init` and follow instructions.
## Authentication
This template assumes that coderd is run in an environment that is authenticated
with AWS. For example, run `aws configure import` to import credentials on the
system and user running coderd. For other ways to authenticate [consult the
Terraform docs](https://registry.terraform.io/providers/hashicorp/aws/latest/docs#authentication-and-configuration).
## Required permissions / policy
This example policy allows Coder to create EC2 instances and modify instances provisioned by Coder.
+1 -23
View File
@@ -7,26 +7,6 @@ terraform {
}
}
variable "access_key" {
description = <<EOT
Create an AWS access key to provision resources with Coder:
- https://console.aws.amazon.com/iam/home#/users
See the template README for an example permissions policy,
if needed.
AWS Access Key ID
EOT
sensitive = true
}
variable "secret_key" {
description = <<EOT
AWS Secret Key
EOT
sensitive = true
}
# Last updated 2022-05-31
# aws ec2 describe-regions | jq -r '[.Regions[].RegionName] | sort'
variable "region" {
@@ -70,9 +50,7 @@ variable "disk_size" {
}
provider "aws" {
region = var.region
access_key = var.access_key
secret_key = var.secret_key
region = var.region
}
data "coder_workspace" "me" {