Penv Cloud
Start free
Docs
Reference

AWS Elastic Beanstalk

Sync secrets into an Elastic Beanstalk environment's properties. Values are limited to letters, digits, spaces and _ . : / = + - @.

Sync secrets into an Elastic Beanstalk environment's properties. Values are limited to letters, digits, spaces and _ . : / = + - @.

Connection

WhatThis provider
VendorAmazon Web Services
Keyelastic-beanstalk-env
Availabilityavailable. You can connect it today.
Credential we holdaws-role
Values read backyes
Activationrestart-on-write

Directions

DirectionWhat it does
importWe read names and values out of the store into your environment.
exportWe write names and values from your environment into the store.

Activation

restart-on-write. When we write a value, the workload restarts.

Conflict policies

DirectionPolicies you can pick
importskip_existing, new_version, fail
exportcreate_only, overwrite, overwrite_and_prune

How syncs work says what each one does.

Connect

You grant us access in your own AWS account. Pick one of these methods in the wizard.

We generate the shared value the grant is conditioned on, so you invent nothing.

Terraform: recommended, the grant is reviewable before it exists

Review the grant in code, then paste the role ARN back. Apply a rendered policy or template. You paste the result back into the wizard.

Set aside about 10 minutes.

  1. Add the snippet to your AWS account's Terraform and apply it.
  2. Paste the penv_role_arn output back here.

It gives you:

NameLabelKindWhat it is
snippetTerraformread only, a block to copy
externalIdExternal IDread only, filled in for youAlready baked into the snippet. Only we can assume the role with it.

You paste back:

FieldLabelKindRequiredWhat it is
roleArnRole ARNtextyesThe ARN the grant printed. We assume it once to check it before saving.

Manual

Create the role manually from the two policies below. Set up the grant by hand in the vendor's console. You paste the result back into the wizard.

Set aside about 10 minutes.

  1. In IAM, create a role for another AWS account and paste the trust policy below.
  2. Attach the permissions policy below as an inline policy.
  3. Paste the role's ARN back here.

It gives you:

NameLabelKindWhat it is
penvAccountIdOur AWS account IDread only, filled in for youThe account the role trusts.
roleNameSuggested role nameread only, filled in for youUnique to this attempt, so it cannot collide with a role another connection made.
externalIdExternal IDread only, filled in for youRequired in the trust policy. Only we can assume the role with it.
trustPolicyTrust policyread only, a block to copy
permissionsPolicyPermissions policyread only, a block to copy

You paste back:

FieldLabelKindRequiredWhat it is
roleArnRole ARNtextyesThe ARN the grant printed. We assume it once to check it before saving.

Connection fields

You set these when you connect. Every mapping on the connection shares them.

FieldLabelKindRequiredAdvancedWhat it is
regionRegiontextyesnoThe region this connection reaches. One connection covers one region. China and GovCloud regions are not supported.
accountIdAccount IDtextyesnoThe account the application is in. The grant names its ARNs exactly.
applicationNameApplicationtextyesnoThe Elastic Beanstalk application this connection may touch. The grant is scoped to it.
roleArnRole ARNread only, filled in for youyesnoThe role we assume. We fill it in from the grant you completed.

Mapping fields

You answer these once per environment you map.

FieldLabelKindRequiredAdvancedWhat it is
environmentNameEnvironmenttextyesnoThe environment whose properties this maps onto. Each write restarts it. A value may hold only letters, digits, spaces and _ . : / = + - @; a push with any other character writes nothing.

Required permissions

We probe for these when we verify the connection.

PermissionDirectionsBlockingWithout it
sts:GetCallerIdentityevery directionyesWe cannot confirm which IAM identity this credential is.
elasticbeanstalk:DescribeConfigurationSettingsevery directionyesPreview cannot list the environment's properties.
elasticbeanstalk:DescribeEnvironmentsexportyesExport cannot tell whether the environment is Ready to take a write.
elasticbeanstalk:UpdateEnvironmentexportyesExport cannot write anything.