Skip to content

Commit 2e76afa

Browse files
committed
Update TTL for prow_secret in secrets manager modules
k8s-s390x-conformance from 4hrs to 12hrs to better align with required secret rotation policies.
1 parent 03d2b31 commit 2e76afa

3 files changed

Lines changed: 5 additions & 5 deletions

File tree

infra/ibmcloud/terraform/k8s-power-conformance/modules/secrets_manager/secrets_manager.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -34,8 +34,8 @@ resource "ibm_sm_iam_credentials_secret" "prow_secret" {
3434
access_groups = [var.pvs_access_group_id]
3535
labels = ["rotate:true"]
3636

37-
//The time-to-live (TTL) or lease duration of generated secret 43200seconds = 12hrs
38-
ttl = "43200"
37+
//The time-to-live (TTL) or lease duration of generated secret 21600seconds = 6hrs
38+
ttl = "21600"
3939
}
4040

4141
resource "ibm_sm_iam_credentials_secret" "janitor_secret" {

infra/ibmcloud/terraform/k8s-s390x-conformance/modules/secrets_manager/secret_manager.tf

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,8 @@ resource "ibm_sm_iam_credentials_secret" "prow_secret" {
3232
access_groups = [var.vpc_build_cluster_access_group_id]
3333
labels = ["rotate:true"]
3434

35-
//The time-to-live (TTL) or lease duration of generated secret 14400seconds = 4hrs
36-
ttl = "14400"
35+
//The time-to-live (TTL) or lease duration of generated secret 43200seconds = 12hrs
36+
ttl = "43200"
3737
}
3838
resource "ibm_sm_iam_credentials_secret" "janitor_secret" {
3939
depends_on = [ibm_sm_iam_credentials_configuration.sm_iam_credentials_configuration_instance]

kubernetes/ibm-s390x/helm/external-secrets.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -94,7 +94,7 @@ extraObjects:
9494
set -o pipefail
9595
9696
go install sigs.k8s.io/provider-ibmcloud-test-infra/secret-manager@71ef4d8
97-
secret-manager rotate --instance-id 0664d47c-fe42-423f-930d-69570443cd15 --labels rotate:true --confirm
97+
secret-manager rotate --instance-id 0664d47c-fe42-423f-930d-69570443cd15 --region eu-de --labels rotate:true --confirm
9898
env:
9999
- name: IBMCLOUD_ENV_FILE
100100
value: "/home/.ibmcloud/api-key"

0 commit comments

Comments
 (0)