defaults.yaml1.6 KB
View on GitHubcomponents:
terraform:
app-config:
metadata:
component: app-config
description: "Publishes resolved app configuration and secrets to SSM Parameter Store."
# Component dependencies declare the apply order in the DAG (consumed by
# `atmos describe dependents`, `--affected` runs, and workflows). This is the
# current form; the legacy `settings.depends_on` map is deprecated.
# https://atmos.tools/stacks/dependencies/components
dependencies:
components:
- name: kms-key
- name: s3-bucket
- name: dynamodb-table
- name: sns-topic
- name: sqs-queue
secrets:
vars:
API_KEY:
description: "Third-party API key for the application."
store: secrets/ssm
required: true
DB_CONFIG:
description: "Structured database credentials (JSON) stored in Secrets Manager."
store: secrets/asm
required: true
vars:
name: app
# Every coordinate is read straight from the upstream component's Terraform
# state, so there are no hand-derived ARNs/names that can drift from what was
# actually deployed (and nothing AWS-account- or endpoint-specific is hardcoded).
kms_key_arn: !terraform.state kms-key key_arn
bucket_id: !terraform.state s3-bucket bucket_id
table_name: !terraform.state dynamodb-table table_name
topic_arn: !terraform.state sns-topic topic_arn
queue_url: !terraform.state sqs-queue queue_url
api_key: !secret API_KEY
db_password: !secret DB_CONFIG | path ".password"