ankurk91/aws-ssm-parameter-sync-action

GitHub Action to sync parameters to AWS SSM :arrows_counterclockwise:

★ 0Forks 0JavaScriptGitHub ↗Compare

Project website ↗

awsssm

README

AWS Systems Manager Parameter Store Sync

tests

A GitHub Action to sync parameters to AWS Systems Manager Parameter Store.

Features

  • Create or update parameters
  • Delete orphan parameters
  • This action assumes that all parameters are SecureString
  • This action assumes that you have prefixed your parameters

Usage

on:
  push:
    branches:
      - main

jobs:
  Deployment:
    runs-on: ubuntu-latest

    steps:
      - name: Configure AWS Credentials
        uses: aws-actions/configure-aws-credentials@v6
        with:
          aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
          aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
          aws-region: ${{ vars.AWS_REGION }}

      - name: Sync SSM parameters
        uses: ankurk91/aws-ssm-parameter-sync-action@v4
        with:
          path_prefix: "/production/"
          parameters: |
            DB_USER: "${{ secrets.DB_USER }}"
            DB_PASSWORD: "${{ secrets.DB_PASSWORD }}"
            DB_DEBUG: "${{ vars.DB_DEBUG }}"

Inputs

Name Required Default Description
path_prefix Yes null SSM path prefix
parameters Yes null YAML mapping of parameter names to values
tier No Standard One of Advanced, Intelligent-Tiering or Standard
kms_key_id No null KMS key ID/ARN/alias for SecureString encryption

Credentials and Region

This action relies on the default behavior of the AWS SDK for Javascript to determine AWS credentials and region. Use the aws-actions/configure-aws-credentials action to configure the GitHub Actions environment with environment variables containing AWS credentials and your desired region.

Permissions

This action requires the following minimum set of permissions:

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ssm:DescribeParameters",
        "ssm:GetParameter",
        "ssm:GetParameters",
        "ssm:GetParametersByPath",
        "ssm:PutParameter",
        "ssm:DeleteParameter",
        "ssm:DeleteParameters"
      ],
      "Resource": "arn:aws:ssm:*:*:parameter/*"
    }
  ]
}

When using a customer-managed kms_key_id, the role also needs kms:Encrypt, kms:Decrypt and kms:GenerateDataKey on that key (granted via the IAM policy and the key policy).

Quoting values

Always quote your values. They are parsed as YAML, so an unquoted 1.10 is stored as 1.1 and a long numeric id loses precision. The action warns on every unquoted number or boolean, and fails the run on a mapping or a sequence, which cannot be stored as a string.

Reference links

License

This repo is licensed under MIT License.

Contributors

ankurk91dependabot[bot]

Issues