Skip to content

Commit 30724d8

Browse files
committed
feat(aws): DatabaseSecret recoveryWindow pass-through; rds.groups fixture immediate deletion
Live run 2 failed re-creating the deterministic secret name inside AWS's 30-day deletion-recovery window from run 1's destroy. recoveryWindow is a documented TERRACONSTRUCTS DEVIATION (CFN deletes immediately; recovery_window_in_days is provider-level); fixture uses Duration.days(0). Live run 3: PASS 44.73s, 13/13, drift oracle clean.
1 parent b791666 commit 30724d8

7 files changed

Lines changed: 28 additions & 8 deletions

File tree

‎integ/aws/storage/apps/rds.groups.ts‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010
// minimal IEngine literals below carry only the fields these constructs read
1111
// (same stand-in idiom as test/aws/storage/rds/parameter-group.test.ts).
1212
import { App, LocalBackend, TerraformOutput } from "cdktn";
13-
import { aws } from "../../../../src";
13+
import { aws, Duration } from "../../../../src";
1414

1515
const environmentName = process.env.ENVIRONMENT_NAME ?? "test";
1616
const region = process.env.AWS_REGION ?? "us-east-1";
@@ -102,6 +102,10 @@ const optionGroup = new aws.storage.rds.OptionGroup(stack, "Options", {
102102

103103
const secret = new aws.storage.rds.DatabaseSecret(stack, "Secret", {
104104
username: "dbadmin",
105+
// Force immediate deletion on destroy so the deterministic secret name can
106+
// be re-created across repeated integ runs (run 2 failed on the 30-day
107+
// recovery window from run 1's destroy).
108+
recoveryWindow: Duration.days(0),
105109
});
106110

107111
new TerraformOutput(stack, "subnet_group_name", {

‎src/aws/storage/rds/database-secret.ts‎

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
import { Annotations } from "cdktn";
44
import type { Construct } from "constructs";
55
import { DEFAULT_PASSWORD_EXCLUDE_CHARS } from "./private/util";
6+
import { Duration } from "../../../duration";
67
import { md5hash } from "../../../helpers-internal";
78
import { AwsStack } from "../../aws-stack";
89
import * as secretsmanager from "../../encryption";
@@ -52,6 +53,20 @@ export interface DatabaseSecretProps {
5253
*/
5354
readonly excludeCharacters?: string;
5455

56+
/**
57+
* The number of days that Secrets Manager waits before it can delete the secret.
58+
*
59+
* TERRACONSTRUCTS DEVIATION: not present upstream (CloudFormation deletes
60+
* secrets immediately on stack delete; deletion recovery is a
61+
* Terraform-provider concept, `recovery_window_in_days`). Exposed as a
62+
* pass-through to `encryption.SecretProps.recoveryWindow` so deterministic
63+
* secret names can be re-created promptly (e.g. integ fixtures use
64+
* `Duration.days(0)`).
65+
*
66+
* @default - AWS default of 30 days
67+
*/
68+
readonly recoveryWindow?: Duration;
69+
5570
/**
5671
* Whether to replace this secret when the criteria for the password change.
5772
*
@@ -119,6 +134,7 @@ export class DatabaseSecret extends secretsmanager.Secret {
119134
excludeCharacters,
120135
},
121136
replicaRegions: props.replicaRegions,
137+
recoveryWindow: props.recoveryWindow,
122138
});
123139

124140
// TERRACONSTRUCTS DEVIATION: upstream overrides the CFN logical ID so that CloudFormation

‎test/aws/storage/rds/__snapshots__/database-secret.test.ts.snap‎

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎test/aws/storage/rds/__snapshots__/option-group.test.ts.snap‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎test/aws/storage/rds/__snapshots__/parameter-group.test.ts.snap‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎test/aws/storage/rds/__snapshots__/subnet-group.test.ts.snap‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎test/aws/storage/rds/__snapshots__/util.test.ts.snap‎

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)