Docs
Reference

AWS SSM Parameter Store (IAM role)

Move parameters to and from an SSM path.

Move parameters to and from an SSM path.

The connection

WhatThis provider
VendorAmazon Web Services
Keyaws-ssm-role
Availabilityavailable. You can connect it today.
Credential penv holdsaws-role
Values read backyes
Activationimmediate

What it moves

DirectionWhat it does
importReads names and values out of the store into penv.
exportWrites names and values from penv into the store.

When a written value goes live

immediate. The running app sees a new value at once.

What happens to a name that exists

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

How you connect

You grant penv access in your own AWS account. Pick one of these in the wizard.

penv generates the shared value the grant is conditioned on, so there is nothing for you to invent.

CloudFormation: recommended, fastest and most secure

One pre-filled stack; Penv-cloud is connected when it finishes. Follow a prepared link into the vendor's console. The vendor calls penv back when the grant lands.

Set aside about 2 minutes.

  1. Confirm you're signed into the AWS account you want to connect. Switch accounts first if you are not.
  2. Open the pre-filled Create Stack page and tick the IAM acknowledgement.
  3. Create the stack and leave this tab open; it flips to Connected on its own.

Terraform

Review the grant in code, then paste the role ARN back. Apply a rendered policy or template. You paste the result back into the wizard.

Set aside about 10 minutes.

  1. Add the snippet to your AWS account's Terraform and apply it.
  2. Paste the penv_role_arn output back here.

It gives you:

NameLabelKindWhat it is
snippetTerraformread only, a block to copy
externalIdExternal IDread only, filled in for youAlready baked into the snippet. Only Penv-cloud can assume the role with it.

You paste back:

FieldLabelKindRequiredWhat it is
roleArnRole ARNtextyesThe ARN the grant printed. We assume it once to check it before saving.

Manual

Create the role manually from the two policies below. Paste a credential you already hold. You paste the result back into the wizard.

Set aside about 10 minutes.

  1. In IAM, create a role for another AWS account and paste the trust policy below.
  2. Attach the permissions policy below as an inline policy.
  3. Paste the role's ARN back here.

It gives you:

NameLabelKindWhat it is
penvAccountIdPenv-cloud AWS account IDread only, filled in for youThe account the role trusts.
roleNameSuggested role nameread only, filled in for youUnique to this attempt, so it cannot collide with a role another connection made.
externalIdExternal IDread only, filled in for youRequired in the trust policy. Only Penv-cloud can assume the role with it.
trustPolicyTrust policyread only, a block to copy
permissionsPolicyPermissions policyread only, a block to copy

You paste back:

FieldLabelKindRequiredWhat it is
roleArnRole ARNtextyesThe ARN the grant printed. We assume it once to check it before saving.

What the connection asks for

Fixed when you connect, and shared by every mapping on it.

FieldLabelKindRequiredAdvancedWhat it is
regionRegiontextyesnoThe region this connection reaches. One connection covers one region.
accountIdAccount IDtextnoyesIf supplied, the generated policy names the account instead of a wildcard.
basePathBase pathtextyesnoThe widest SSM path this connection may touch. Every sync scope will sit under it.
roleArnRole ARNread only, filled in for youyesnoThe role we assume. Filled in by the grant you just completed.
engineRoleArnsAssumable engine rolestextnoyesOnly for dynamic secrets, and fixed once the connection exists. Comma-separated role ARNs this connection may assume; leave empty to grant none.

What a mapping asks for

Answered once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
pathSSM pathtextyesnoMaps onto this environment. Will sit under the connection's base path.
recursiveInclude nested pathsyes or noyesyesNested SSM paths become the parameter's path prefix with us. Starts at true.

Permissions it needs

penv probes for these when it verifies the connection.

PermissionDirectionsBlockingWithout it
sts:GetCallerIdentityevery directionyesWe cannot confirm which IAM identity this credential is.
ssm:GetParametersByPathevery directionyesPreview cannot list what is under this path.
kms:DecryptimportnoSecureString parameters will import empty
ssm:PutParameterexportyesExport cannot write anything.
kms:EncryptexportyesExport cannot write SecureString parameters.
ssm:DeleteParameterexportnoThe overwrite_and_prune policy cannot remove remote keys.