A GitHub Action to sync parameters to AWS Systems Manager Parameter Store.
- Create or update parameters
- Delete orphan parameters
- This action assumes that all parameters are
SecureString - This action assumes that you have prefixed your parameters
on:
push:
branches:
- main
jobs:
Deployment:
runs-on: ubuntu-latest
steps:
- name: Configure AWS Credentials
uses: aws-actions/configure-aws-credentials@v6
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: ${{ vars.AWS_REGION }}
- name: Sync SSM parameters
uses: ankurk91/aws-ssm-parameter-sync-action@v4
with:
path_prefix: "/production/"
parameters: |
DB_USER: "${{ secrets.DB_USER }}"
DB_PASSWORD: "${{ secrets.DB_PASSWORD }}"
DB_DEBUG: "${{ vars.DB_DEBUG }}"| Name | Required | Default | Description |
|---|---|---|---|
path_prefix |
Yes | null |
SSM path prefix |
parameters |
Yes | null |
YAML mapping of parameter names to values |
tier |
No | Standard |
One of Advanced, Intelligent-Tiering or Standard |
kms_key_id |
No | null |
KMS key ID/ARN/alias for SecureString encryption |
This action relies on the default behavior of the AWS SDK for Javascript to determine AWS credentials and region. Use the aws-actions/configure-aws-credentials action to configure the GitHub Actions environment with environment variables containing AWS credentials and your desired region.
This action requires the following minimum set of permissions:
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"ssm:DescribeParameters",
"ssm:GetParameter",
"ssm:GetParameters",
"ssm:GetParametersByPath",
"ssm:PutParameter",
"ssm:DeleteParameter",
"ssm:DeleteParameters"
],
"Resource": "arn:aws:ssm:*:*:parameter/*"
}
]
}When using a customer-managed kms_key_id, the role also needs kms:Encrypt, kms:Decrypt and
kms:GenerateDataKey on that key (granted via the IAM policy and the key policy).
Always quote your values. They are parsed as YAML, so an unquoted 1.10 is stored as 1.1 and a
long numeric id loses precision. The action warns on every unquoted number or boolean, and fails
the run on a mapping or a sequence, which cannot be stored as a string.
This repo is licensed under MIT License.