AWS Elastic Beanstalk
Sync secrets into an Elastic Beanstalk environment's properties. Values are limited to letters, digits, spaces and _ . : / = + - @.
Sync secrets into an Elastic Beanstalk environment's properties. Values are limited to letters, digits, spaces and _ . : / = + - @.
Connection
| What | This provider |
|---|---|
| Vendor | Amazon Web Services |
| Key | elastic-beanstalk-env |
| Availability | available. You can connect it today. |
| Credential we hold | aws-role |
| Values read back | yes |
| Activation | restart-on-write |
Directions
| Direction | What it does |
|---|---|
import | We read names and values out of the store into your environment. |
export | We write names and values from your environment into the store. |
Activation
restart-on-write. When we write a value, the workload restarts.
Conflict policies
| Direction | Policies you can pick |
|---|---|
import | skip_existing, new_version, fail |
export | create_only, overwrite, overwrite_and_prune |
How syncs work says what each one does.
Connect
You grant us access in your own AWS account. Pick one of these methods in the wizard.
We generate the shared value the grant is conditioned on, so you invent nothing.
Terraform: recommended, the grant is reviewable before it exists
Review the grant in code, then paste the role ARN back. Apply a rendered policy or template. You paste the result back into the wizard.
Set aside about 10 minutes.
- Add the snippet to your AWS account's Terraform and apply it.
- Paste the
penv_role_arnoutput back here.
It gives you:
| Name | Label | Kind | What it is |
|---|---|---|---|
snippet | Terraform | read only, a block to copy | |
externalId | External ID | read only, filled in for you | Already baked into the snippet. Only we can assume the role with it. |
You paste back:
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
roleArn | Role ARN | text | yes | The ARN the grant printed. We assume it once to check it before saving. |
Manual
Create the role manually from the two policies below. Set up the grant by hand in the vendor's console. You paste the result back into the wizard.
Set aside about 10 minutes.
- In IAM, create a role for another AWS account and paste the trust policy below.
- Attach the permissions policy below as an inline policy.
- Paste the role's ARN back here.
It gives you:
| Name | Label | Kind | What it is |
|---|---|---|---|
penvAccountId | Our AWS account ID | read only, filled in for you | The account the role trusts. |
roleName | Suggested role name | read only, filled in for you | Unique to this attempt, so it cannot collide with a role another connection made. |
externalId | External ID | read only, filled in for you | Required in the trust policy. Only we can assume the role with it. |
trustPolicy | Trust policy | read only, a block to copy | |
permissionsPolicy | Permissions policy | read only, a block to copy |
You paste back:
| Field | Label | Kind | Required | What it is |
|---|---|---|---|---|
roleArn | Role ARN | text | yes | The ARN the grant printed. We assume it once to check it before saving. |
Connection fields
You set these when you connect. Every mapping on the connection shares them.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
region | Region | text | yes | no | The region this connection reaches. One connection covers one region. China and GovCloud regions are not supported. |
accountId | Account ID | text | yes | no | The account the application is in. The grant names its ARNs exactly. |
applicationName | Application | text | yes | no | The Elastic Beanstalk application this connection may touch. The grant is scoped to it. |
roleArn | Role ARN | read only, filled in for you | yes | no | The role we assume. We fill it in from the grant you completed. |
Mapping fields
You answer these once per environment you map.
| Field | Label | Kind | Required | Advanced | What it is |
|---|---|---|---|---|---|
environmentName | Environment | text | yes | no | The environment whose properties this maps onto. Each write restarts it. A value may hold only letters, digits, spaces and _ . : / = + - @; a push with any other character writes nothing. |
Required permissions
We probe for these when we verify the connection.
| Permission | Directions | Blocking | Without it |
|---|---|---|---|
sts:GetCallerIdentity | every direction | yes | We cannot confirm which IAM identity this credential is. |
elasticbeanstalk:DescribeConfigurationSettings | every direction | yes | Preview cannot list the environment's properties. |
elasticbeanstalk:DescribeEnvironments | export | yes | Export cannot tell whether the environment is Ready to take a write. |
elasticbeanstalk:UpdateEnvironment | export | yes | Export cannot write anything. |