-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathtemplate.yaml
59 lines (53 loc) · 1.67 KB
/
template.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
AWSTemplateFormatVersion: '2010-09-09'
Transform: AWS::Serverless-2016-10-31
Description: >
secret-injection-demo
Sample SAM Template for secret-injection-demo
Parameters:
SecretArn:
Type: String
Description: the ARN of the secret stored in AWS Secrets Manager
# More info about Globals: https://github.com/awslabs/serverless-application-model/blob/master/docs/globals.rst
Globals:
Function:
Timeout: 3
Resources:
HelloWorldFunction:
Type: AWS::Serverless::Function
Properties:
CodeUri: hello_world/
Handler: app.lambda_handler
Runtime: python3.9
MemorySize: 128
Architectures:
- x86_64
Layers:
- !Ref SecretsInjectorLayer
Policies:
- AWSSecretsManagerGetSecretValuePolicy:
SecretArn: !Ref SecretArn
Environment:
Variables:
AWS_LAMBDA_EXEC_WRAPPER: /opt/bin/bootstrap
DB_USERNAME: !Sub "{{inject:secretsmanager:${SecretArn}:SecretString:username}}"
DB_PASSWORD: !Sub "{{inject:secretsmanager:${SecretArn}:SecretString:password}}"
Events:
HelloWorld:
Type: Api
Properties:
Path: /
Method: get
SecretsInjectorLayer:
Type: AWS::Serverless::LayerVersion
Properties:
ContentUri: layer/
Metadata:
BuildMethod: makefile
BuildArchitecture: x86_64
Outputs:
HelloWorldApi:
Description: "API Gateway endpoint URL for Prod stage for Hello World function"
Value: !Sub "https://${ServerlessRestApi}.execute-api.${AWS::Region}.amazonaws.com/Prod/"
HelloWorldFunction:
Description: "Hello World Lambda Function ARN"
Value: !GetAtt HelloWorldFunction.Arn