HC-vault-on-aws-FORK/kms.tf

16 lines
385 B
Terraform
Raw Normal View History

2020-04-10 02:37:14 +00:00
# AWS KMS Key
resource "aws_kms_key" "seal" {
description = "The KMS key to unseal Vault."
enable_key_rotation = true
tags = merge(
{ "Name" = "${var.main_project_tag}-seal-key" },
{ "Project" = var.main_project_tag },
var.kms_tags
)
}
resource "aws_kms_alias" "seal" {
name = "alias/${var.main_project_tag}-seal-key"
target_key_id = aws_kms_key.seal.key_id
}