Skip to content

Commit

Permalink
feat: Use a secret for GH App key
Browse files Browse the repository at this point in the history
  • Loading branch information
xaviermignot committed Feb 19, 2024
1 parent bf64490 commit 708dedd
Show file tree
Hide file tree
Showing 2 changed files with 24 additions and 6 deletions.
10 changes: 4 additions & 6 deletions infra/01-prerequisites/resources.bicep
Original file line number Diff line number Diff line change
Expand Up @@ -48,14 +48,12 @@ module keyVault '../modules/keyVault.bicep' = {
}
}

module keyVaultGitHubAppKey '../modules/keyVaultKey.bicep' = {
module keyVaultGitHubAppKey '../modules/keyVaultSecret.bicep' = {
name: 'deploy-${project}-kv-github-app-key'
params: {
keyName: 'key-github-app'
keyValue: gitHubAppKey
location: location
project: project
tags: union(tags, {module: 'keyVaultKey.bicep'})
secretName: 'key-github-app'
secretValue: gitHubAppKey
tags: union(tags, {module: 'keyVaultSecret.bicep'})
vaultName: keyVault.outputs.name
}
}
Expand Down
20 changes: 20 additions & 0 deletions infra/modules/keyVaultSecret.bicep
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
param tags {
*: string
}
param vaultName string
param secretName string
@secure()
param secretValue string

resource kv 'Microsoft.KeyVault/vaults@2023-07-01' existing = {
name: vaultName
}

resource kvSecret 'Microsoft.KeyVault/vaults/secrets@2023-07-01' = {
name: secretName
parent: kv
tags: tags
properties: {
value: secretValue
}
}

0 comments on commit 708dedd

Please sign in to comment.