Skip to content
This repository was archived by the owner on Jan 16, 2025. It is now read-only.

Commit 5d314f2

Browse files
authored
fix(multi-runner): enable SSE by default for runner-binaries bucket (#3274)
1 parent b7df70f commit 5d314f2

File tree

2 files changed

+8
-2
lines changed

2 files changed

+8
-2
lines changed

Diff for: modules/multi-runner/README.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -148,7 +148,7 @@ module "multi-runner" {
148148
| <a name="input_role_path"></a> [role\_path](#input\_role\_path) | The path that will be added to the role; if not set, the environment name will be used. | `string` | `null` | no |
149149
| <a name="input_role_permissions_boundary"></a> [role\_permissions\_boundary](#input\_role\_permissions\_boundary) | Permissions boundary that will be added to the created role for the lambda. | `string` | `null` | no |
150150
| <a name="input_runner_additional_security_group_ids"></a> [runner\_additional\_security\_group\_ids](#input\_runner\_additional\_security\_group\_ids) | (optional) List of additional security groups IDs to apply to the runner | `list(string)` | `[]` | no |
151-
| <a name="input_runner_binaries_s3_sse_configuration"></a> [runner\_binaries\_s3\_sse\_configuration](#input\_runner\_binaries\_s3\_sse\_configuration) | Map containing server-side encryption configuration for runner-binaries S3 bucket. | `any` | `{}` | no |
151+
| <a name="input_runner_binaries_s3_sse_configuration"></a> [runner\_binaries\_s3\_sse\_configuration](#input\_runner\_binaries\_s3\_sse\_configuration) | Map containing server-side encryption configuration for runner-binaries S3 bucket. | `any` | <pre>{<br> "rule": {<br> "apply_server_side_encryption_by_default": {<br> "sse_algorithm": "AES256"<br> }<br> }<br>}</pre> | no |
152152
| <a name="input_runner_binaries_s3_versioning"></a> [runner\_binaries\_s3\_versioning](#input\_runner\_binaries\_s3\_versioning) | Status of S3 versioning for runner-binaries S3 bucket. Once set to Enabled the change cannot be reverted via Terraform! | `string` | `"Disabled"` | no |
153153
| <a name="input_runner_binaries_syncer_lambda_timeout"></a> [runner\_binaries\_syncer\_lambda\_timeout](#input\_runner\_binaries\_syncer\_lambda\_timeout) | Time out of the binaries sync lambda in seconds. | `number` | `300` | no |
154154
| <a name="input_runner_binaries_syncer_lambda_zip"></a> [runner\_binaries\_syncer\_lambda\_zip](#input\_runner\_binaries\_syncer\_lambda\_zip) | File location of the binaries sync lambda zip file. | `string` | `null` | no |

Diff for: modules/multi-runner/variables.tf

+7-1
Original file line numberDiff line numberDiff line change
@@ -323,7 +323,13 @@ variable "lambda_principals" {
323323
variable "runner_binaries_s3_sse_configuration" {
324324
description = "Map containing server-side encryption configuration for runner-binaries S3 bucket."
325325
type = any
326-
default = {}
326+
default = {
327+
rule = {
328+
apply_server_side_encryption_by_default = {
329+
sse_algorithm = "AES256"
330+
}
331+
}
332+
}
327333
}
328334

329335
variable "runner_binaries_s3_versioning" {

0 commit comments

Comments
 (0)