Files
kodekloud-engineer/terraform/task-20.md

2.9 KiB

Assignment

The Nautilus DevOps team needs to create an SSM parameter in AWS with the following requirements:

  1. The name of the parameter should be nautilus-ssm-parameter.

  2. Set the parameter type to String.

  3. Set the parameter value to nautilus-value.

  4. The parameter should be created in the us-east-1 region.

  5. Ensure the parameter is successfully created using terraform and can be retrieved when the task is completed.

The Terraform working directory is /home/bob/terraform. Create the main.tf file (do not create a different .tf file) to accomplish this task.

Note: Right-click under the EXPLORER section in VS Code and select Open in Integrated Terminal to launch the terminal.

Solution

SSM Parameter — nautilus-ssm-parameter

Terraform solution to create a plaintext String parameter in AWS Systems Manager Parameter Store.

main.tf

terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 6.0"
    }
  }
}

provider "aws" {
  region = "us-east-1"
}

resource "aws_ssm_parameter" "nautilus" {
  name  = "nautilus-ssm-parameter"
  type  = "String"
  value = "nautilus-value"
}

How to run

cd /home/bob/terraform
terraform init
terraform apply -auto-approve

How it works

aws_ssm_parameter

One resource covers the whole task. SSM Parameter Store is a managed key/value store for configuration data and secrets, and this creates a single entry in it.

  • name = "nautilus-ssm-parameter" — the parameter's key/path. Names can be hierarchical (e.g. /app/prod/db-url); a flat name like this one is stored at the root.

  • type = "String" — the parameter type. The three types are:

    • String — a single plaintext value (used here).
    • StringList — a comma-separated list of values.
    • SecureString — an encrypted value backed by a KMS key.

    The task wants a plain String, so no encryption or KMS key is involved.

  • value = "nautilus-value" — the stored value. Because the type is String, it's held as-is in plaintext and returned verbatim on read.

  • Region comes from the provider (us-east-1). Unlike IAM, SSM parameters are regional — a parameter created here is only visible in us-east-1, which satisfies requirement #4.

Retrieval (requirement #5)

The task asks that the parameter be retrievable once created. Nothing extra is needed in the config for that — a String parameter is readable immediately via the SSM API. The verification command below confirms it.

Note: if this were a SecureString, you'd need --with-decryption on read to get the plaintext back. For a plain String that flag is unnecessary.

Verify

aws ssm get-parameter --name nautilus-ssm-parameter \
  --query 'Parameter.{Name:Name,Type:Type,Value:Value}'

Expected:

{
  "Name": "nautilus-ssm-parameter",
  "Type": "String",
  "Value": "nautilus-value"
}