Skip to content

Commit e605857

Browse files
author
olamide
committed
Mark the header variable input as sensitive
1 parent ee8b8cb commit e605857

File tree

2 files changed

+6
-2
lines changed

2 files changed

+6
-2
lines changed

aws/waf/main.tf

+4-2
Original file line numberDiff line numberDiff line change
@@ -13,7 +13,7 @@ resource "aws_wafv2_web_acl" "main" {
1313
metric_name = "${var.name}-cloudfront-web-acl"
1414
}
1515

16-
dynamic "header_rule" {
16+
dynamic "rule" {
1717
for_each = var.header_match_rules
1818
content {
1919
name = "${header_rule.value["name"]}-header-match-rule"
@@ -34,7 +34,9 @@ resource "aws_wafv2_web_acl" "main" {
3434
statement {
3535
byte_match_statement {
3636
field_to_match {
37-
single_header = lower(header_rule.value["header_name"])
37+
single_header {
38+
name = lower(header_rule.value["header_name"])
39+
}
3840
}
3941

4042
positional_constraint = "CONTAINS"

aws/waf/variables.tf

+2
Original file line numberDiff line numberDiff line change
@@ -56,6 +56,8 @@ variable "header_match_rules" {
5656
}))
5757

5858
default = null
59+
60+
sensitive = true
5961
}
6062

6163
variable "allowed_ip_list" {

0 commit comments

Comments
 (0)