Convert random_string to random_password in RDS module.#90
Open
rin-skylight wants to merge 1 commit intomainfrom
Open
Convert random_string to random_password in RDS module.#90rin-skylight wants to merge 1 commit intomainfrom
rin-skylight wants to merge 1 commit intomainfrom
Conversation
shanice-skylight
approved these changes
Oct 9, 2024
Collaborator
shanice-skylight
left a comment
There was a problem hiding this comment.
Straightforward change, good catch.
alismx
approved these changes
Oct 9, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PULL REQUEST
Summary
Previously, the RDS terraform module used
random_stringto generate a password for the database. This is dangerous, asrandom_stringis not marked as sensitive. Values generated using this resource can be viewed in the console, and might be recovered by a malicious actor.This PR replaces
random_stringwithrandom_password, which guarantees handling as a sensitive value.Related Issue
Fixes #89
Additional Information
See below for an example of how

random_stringis currently handled. It appears as though Terraform is automatically converting the object for safety, but this code change should guarantee proper handling.