Skip to content

refactor(parameters): moved ssm resource creation to AwsCustomResource #1319

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 1 addition & 13 deletions packages/parameters/tests/e2e/ssmProvider.class.test.ts
Original file line number Diff line number Diff line change
Expand Up @@ -22,10 +22,7 @@ import {
TEARDOWN_TIMEOUT,
TEST_CASE_TIMEOUT
} from './constants';
import {
createSecureStringProvider,
createSSMSecureString
} from '../helpers/parametersUtils';
import { createSSMSecureString } from '../helpers/parametersUtils';

const runtime: string = process.env.RUNTIME || 'nodejs18x';

Expand Down Expand Up @@ -127,13 +124,6 @@ describe(`parameters E2E tests (ssmProvider) for runtime: ${runtime}`, () => {
runtime,
});

// Create Custom Resource provider:
// will be used to create some SSM parameters not supported by CDK
const provider = createSecureStringProvider({
stack,
parametersPrefix: `${RESOURCE_NAME_PREFIX}-${runtime}-${uuid.substring(0,5)}`
});

// Create SSM parameters
const parameterGetA = new StringParameter(stack, 'Param-a', {
parameterName: paramA,
Expand All @@ -146,15 +136,13 @@ describe(`parameters E2E tests (ssmProvider) for runtime: ${runtime}`, () => {

const parameterEncryptedA = createSSMSecureString({
stack,
provider,
id: 'Param-encrypted-a',
name: paramEncryptedA,
value: paramEncryptedAValue,
});

const parameterEncryptedB = createSSMSecureString({
stack,
provider,
id: 'Param-encrypted-b',
name: paramEncryptedB,
value: paramEncryptedBValue,
Expand Down
80 changes: 24 additions & 56 deletions packages/parameters/tests/helpers/parametersUtils.ts
Original file line number Diff line number Diff line change
@@ -1,9 +1,5 @@
import { Stack, RemovalPolicy, CustomResource, Duration } from 'aws-cdk-lib';
import { PhysicalResourceId, Provider } from 'aws-cdk-lib/custom-resources';
import { RetentionDays } from 'aws-cdk-lib/aws-logs';
import { NodejsFunction } from 'aws-cdk-lib/aws-lambda-nodejs';
import { Runtime } from 'aws-cdk-lib/aws-lambda';
import { PolicyStatement } from 'aws-cdk-lib/aws-iam';
import { Stack, RemovalPolicy } from 'aws-cdk-lib';
import { PhysicalResourceId } from 'aws-cdk-lib/custom-resources';
import { StringParameter, IStringParameter } from 'aws-cdk-lib/aws-ssm';
import { Table, TableProps, BillingMode } from 'aws-cdk-lib/aws-dynamodb';
import {
Expand Down Expand Up @@ -138,70 +134,43 @@ const createAppConfigConfigurationProfile = (options: CreateAppConfigConfigurati
});
};

export type CreateSecureStringProviderOptions = {
stack: Stack
parametersPrefix: string
};

const createSecureStringProvider = (options: CreateSecureStringProviderOptions): Provider => {
const { stack, parametersPrefix } = options;

const ssmSecureStringHandlerFn = new NodejsFunction(
stack,
'ssm-securestring-handler',
{
entry: 'tests/helpers/ssmSecureStringCdk.ts',
handler: 'handler',
bundling: {
minify: true,
sourceMap: true,
target: 'es2020',
externalModules: [],
},
runtime: Runtime.NODEJS_18_X,
timeout: Duration.seconds(15),
});
ssmSecureStringHandlerFn.addToRolePolicy(
new PolicyStatement({
actions: [
'ssm:PutParameter',
'ssm:DeleteParameter',
],
resources: [
`arn:aws:ssm:${stack.region}:${stack.account}:parameter/${parametersPrefix}*`,
],
}),
);

return new Provider(stack, 'ssm-secure-string-provider', {
onEventHandler: ssmSecureStringHandlerFn,
logRetention: RetentionDays.ONE_DAY,
});
};

export type CreateSSMSecureStringOptions = {
stack: Stack
provider: Provider
id: string
name: string
value: string
};

const createSSMSecureString = (options: CreateSSMSecureStringOptions): IStringParameter => {
const { stack, provider, id, name, value } = options;
const { stack, id, name, value } = options;

new CustomResource(stack, `custom-${id}`, {
serviceToken: provider.serviceToken,
properties: {
Name: name,
Value: value,
const paramCreator = new AwsCustomResource(stack, `create-${id}`, {
onCreate: {
service: 'SSM',
action: 'putParameter',
parameters: {
Name: name,
Value: value,
Type: 'SecureString',
},
physicalResourceId: PhysicalResourceId.of(id),
},
onDelete: {
service: 'SSM',
action: 'deleteParameter',
parameters: {
Name: name,
},
},
policy: AwsCustomResourcePolicy.fromSdkCalls({
resources: AwsCustomResourcePolicy.ANY_RESOURCE,
}),
});

const param = StringParameter.fromSecureStringParameterAttributes(stack, id, {
parameterName: name,
});
param.node.addDependency(provider);
param.node.addDependency(paramCreator);

return param;
};
Expand Down Expand Up @@ -237,6 +206,5 @@ export {
createBaseAppConfigResources,
createAppConfigConfigurationProfile,
createSSMSecureString,
createSecureStringProvider,
putDynamoDBItem,
};
54 changes: 0 additions & 54 deletions packages/parameters/tests/helpers/ssmSecureStringCdk.ts

This file was deleted.