diff --git a/terraform/environments/core-logging/cortex.tf b/terraform/environments/core-logging/cortex.tf index 5d054cee4..eef74aa1c 100644 --- a/terraform/environments/core-logging/cortex.tf +++ b/terraform/environments/core-logging/cortex.tf @@ -254,24 +254,6 @@ data "aws_kms_alias" "secrets" { name = "alias/secrets_key" } -resource "aws_secretsmanager_secret" "logging" { - # checkov:skip=CKV2_AWS_57 - provider = aws.modernisation-platform - kms_key_id = data.aws_kms_alias.secrets.target_key_id - name = "core_logging_bucket_arns" - recovery_window_in_days = 0 - tags = local.tags -} - -resource "aws_secretsmanager_secret_version" "logging" { - provider = aws.modernisation-platform - secret_id = aws_secretsmanager_secret.logging.id - secret_string = jsonencode({ - for key in local.cortex_logging_buckets : - key => aws_s3_bucket.logging[key].arn - }) -} - resource "aws_iam_user" "cortex_xsiam_user" { #checkov:skip=CKV_AWS_273: This has been agreed by the TA that for this purpose an IAM user account can be used. name = "cortex_xsiam_user" diff --git a/terraform/environments/core-logging/secrets.tf b/terraform/environments/core-logging/secrets.tf index c0c48b280..5a52eda8c 100644 --- a/terraform/environments/core-logging/secrets.tf +++ b/terraform/environments/core-logging/secrets.tf @@ -20,14 +20,3 @@ data "aws_secretsmanager_secret_version" "pagerduty_integration_keys" { provider = aws.modernisation-platform secret_id = data.aws_secretsmanager_secret.pagerduty_integration_keys.id } - -# Get the ARNs of the logging buckets in `core-logging` -data "aws_secretsmanager_secret" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - name = "core_logging_bucket_arns" -} - -data "aws_secretsmanager_secret_version" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - secret_id = data.aws_secretsmanager_secret.core_logging_bucket_arns.id -} diff --git a/terraform/environments/core-network-services/secrets.tf b/terraform/environments/core-network-services/secrets.tf index 61b2fbfe7..59b2dfad2 100644 --- a/terraform/environments/core-network-services/secrets.tf +++ b/terraform/environments/core-network-services/secrets.tf @@ -21,17 +21,6 @@ data "aws_secretsmanager_secret_version" "pagerduty_integration_keys" { secret_id = data.aws_secretsmanager_secret.pagerduty_integration_keys.id } -# Get the ARNs of the logging buckets in `core-logging` -data "aws_secretsmanager_secret" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - name = "core_logging_bucket_arns" -} - -data "aws_secretsmanager_secret_version" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - secret_id = data.aws_secretsmanager_secret.core_logging_bucket_arns.id -} - # Environment logging secret KMS key resource "aws_kms_key" "environment_logging" { description = "environment-logging" diff --git a/terraform/environments/core-security/secrets.tf b/terraform/environments/core-security/secrets.tf index c0c48b280..5a52eda8c 100644 --- a/terraform/environments/core-security/secrets.tf +++ b/terraform/environments/core-security/secrets.tf @@ -20,14 +20,3 @@ data "aws_secretsmanager_secret_version" "pagerduty_integration_keys" { provider = aws.modernisation-platform secret_id = data.aws_secretsmanager_secret.pagerduty_integration_keys.id } - -# Get the ARNs of the logging buckets in `core-logging` -data "aws_secretsmanager_secret" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - name = "core_logging_bucket_arns" -} - -data "aws_secretsmanager_secret_version" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - secret_id = data.aws_secretsmanager_secret.core_logging_bucket_arns.id -} diff --git a/terraform/environments/core-shared-services/secrets.tf b/terraform/environments/core-shared-services/secrets.tf index c0c48b280..5a52eda8c 100644 --- a/terraform/environments/core-shared-services/secrets.tf +++ b/terraform/environments/core-shared-services/secrets.tf @@ -20,14 +20,3 @@ data "aws_secretsmanager_secret_version" "pagerduty_integration_keys" { provider = aws.modernisation-platform secret_id = data.aws_secretsmanager_secret.pagerduty_integration_keys.id } - -# Get the ARNs of the logging buckets in `core-logging` -data "aws_secretsmanager_secret" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - name = "core_logging_bucket_arns" -} - -data "aws_secretsmanager_secret_version" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - secret_id = data.aws_secretsmanager_secret.core_logging_bucket_arns.id -} diff --git a/terraform/environments/core-vpc/secrets.tf b/terraform/environments/core-vpc/secrets.tf index c0c48b280..5a52eda8c 100644 --- a/terraform/environments/core-vpc/secrets.tf +++ b/terraform/environments/core-vpc/secrets.tf @@ -20,14 +20,3 @@ data "aws_secretsmanager_secret_version" "pagerduty_integration_keys" { provider = aws.modernisation-platform secret_id = data.aws_secretsmanager_secret.pagerduty_integration_keys.id } - -# Get the ARNs of the logging buckets in `core-logging` -data "aws_secretsmanager_secret" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - name = "core_logging_bucket_arns" -} - -data "aws_secretsmanager_secret_version" "core_logging_bucket_arns" { - provider = aws.modernisation-platform - secret_id = data.aws_secretsmanager_secret.core_logging_bucket_arns.id -}