Skip to content

Commit 7f466cd

Browse files
authored
fix: enable kms key rotation as default (#4)
1 parent 9d058d6 commit 7f466cd

File tree

2 files changed

+8
-6
lines changed

2 files changed

+8
-6
lines changed

README.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -84,13 +84,13 @@ No outputs.
8484

8585
- resource.aws_cloudwatch_log_metric_filter.main (main.tf#24)
8686
- resource.aws_cloudwatch_metric_alarm.main (main.tf#38)
87-
- resource.aws_kms_alias.main (main.tf#69)
87+
- resource.aws_kms_alias.main (main.tf#71)
8888
- resource.aws_kms_key.main (main.tf#59)
89-
- resource.aws_sns_topic.main (main.tf#108)
90-
- resource.awscc_chatbot_slack_channel_configuration.main (main.tf#118)
89+
- resource.aws_sns_topic.main (main.tf#110)
90+
- resource.awscc_chatbot_slack_channel_configuration.main (main.tf#120)
9191
- data source.aws_caller_identity.current (main.tf#18)
9292
- data source.aws_cloudwatch_log_group.cloudtrail (main.tf#20)
93-
- data source.aws_iam_policy_document.kms (main.tf#76)
93+
- data source.aws_iam_policy_document.kms (main.tf#78)
9494

9595
# Examples
9696
### Complete

main.tf

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -59,9 +59,11 @@ resource "aws_cloudwatch_metric_alarm" "main" {
5959
resource "aws_kms_key" "main" {
6060
count = var.sns_kms_master_key_id == null ? 1 : 0
6161

62-
description = "KMS key for CloudTrail alerts SNS topic."
62+
description = "KMS key for CloudTrail alerts SNS topic."
63+
policy = data.aws_iam_policy_document.kms[0].json
64+
6365
deletion_window_in_days = 7
64-
policy = data.aws_iam_policy_document.kms[0].json
66+
enable_key_rotation = true
6567

6668
tags = var.tags
6769
}

0 commit comments

Comments
 (0)