Skip to content

Commit 8a8e477

Browse files
backport of commit d7bb0ad (#30746)
Co-authored-by: Tin Vo <[email protected]>
1 parent 51df67e commit 8a8e477

File tree

2 files changed

+7
-2
lines changed
  • enos/modules/verify_secrets_engines/modules

2 files changed

+7
-2
lines changed

enos/modules/verify_secrets_engines/modules/create/aws/aws.tf

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -76,11 +76,16 @@ data "aws_caller_identity" "current" {}
7676

7777
data "aws_region" "current" {}
7878

79-
# Using Pre-made policy and role
79+
# The "DemoUser" policy is a predefined policy created by the security team.
80+
# This policy grants the necessary AWS permissions required for role generation via Vault.
81+
# Reference: https://github.com/hashicorp/honeybee-templates/blob/main/templates/iam_policy/DemoUser.yaml
8082
data "aws_iam_policy" "premade_demo_user_policy" {
8183
name = "DemoUser"
8284
}
8385

86+
# This role was provisioned by the security team using the repository referenced below.
87+
# This role includes the necessary policies to enable AWS credential generation and rotation via Vault.
88+
# Reference: https://github.com/hashicorp/honeybee-templates/blob/main/templates/iam_role/vault-assumed-role-credentials-demo.yaml
8489
data "aws_iam_role" "premade_demo_assumed_role" {
8590
name = "vault-assumed-role-credentials-demo"
8691
}

enos/modules/verify_secrets_engines/modules/read/aws/aws.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ variable "verify_aws_engine_creds" {
4242
type = bool
4343
}
4444

45-
# Verify PKI Certificate
45+
# Verify AWS Engine
4646
resource "enos_remote_exec" "aws_verify_new_creds" {
4747
for_each = var.hosts
4848

0 commit comments

Comments
 (0)