Skip to content

Commit

Permalink
chore: flag certs as sensitive in cloudsql terraform output (#1007)
Browse files Browse the repository at this point in the history
[#186876337](https://www.pivotaltracker.com/story/show/186876337)

Co-authored-by: George Blue <blgm@users.noreply.github.com>
  • Loading branch information
pivotal-marcela-campo and blgm authored Jan 22, 2024
1 parent 19687ad commit 11714c4
Show file tree
Hide file tree
Showing 2 changed files with 16 additions and 4 deletions.
10 changes: 8 additions & 2 deletions terraform/cloudsql/mysql/provision/outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,14 @@ output "password" {
value = google_sql_user.admin_user.password
}

output "sslrootcert" { value = google_sql_database_instance.instance.server_ca_cert.0.cert }
output "sslcert" { value = google_sql_ssl_cert.client_cert.cert }
output "sslrootcert" {
sensitive = true
value = google_sql_database_instance.instance.server_ca_cert.0.cert
}
output "sslcert" {
sensitive = true
value = google_sql_ssl_cert.client_cert.cert
}
output "sslkey" {
value = google_sql_ssl_cert.client_cert.private_key
sensitive = true
Expand Down
10 changes: 8 additions & 2 deletions terraform/cloudsql/postgresql/provision/outputs.tf
Original file line number Diff line number Diff line change
Expand Up @@ -9,10 +9,16 @@ output "password" {
}
output "require_ssl" { value = var.require_ssl }

output "sslcert" { value = google_sql_ssl_cert.client_cert.cert }
output "sslcert" {
sensitive = true
value = google_sql_ssl_cert.client_cert.cert
}
output "sslkey" {
value = google_sql_ssl_cert.client_cert.private_key
sensitive = true
}
output "sslrootcert" { value = google_sql_database_instance.instance.server_ca_cert.0.cert }
output "sslrootcert" {
sensitive = true
value = google_sql_database_instance.instance.server_ca_cert.0.cert
}

0 comments on commit 11714c4

Please sign in to comment.