#!/bin/bash if [ "$1" != "" ]; then # should be an arn cmd[0]="$AWS secretsmanager describe-secret --secret-id $1" else cmd[0]="$AWS secretsmanager list-secrets" fi pref[0]="SecretList" tft[0]="aws_secretsmanager_secret" idfilt[0]="ARN" #rm -f ${tft[0]}.tf for c in `seq 0 0`; do cm=${cmd[$c]} ttft=${tft[(${c})]} #echo $cm awsout=`eval $cm 2> /dev/null` if [ "$awsout" == "" ];then echo "$cm : You don't have access for this resource" exit fi if [ "$1" != "" ]; then count=1 else count=`echo $awsout | jq ".${pref[(${c})]} | length"` fi if [ "$count" -gt "0" ]; then count=`expr $count - 1` for i in `seq 0 $count`; do echo $i if [[ $1 != "" ]];then cname=$(echo $1) else cname=`echo $awsout | jq ".${pref[(${c})]}[(${i})].${idfilt[(${c})]}" | tr -d '"'` fi rname=${cname//:/_} && rname=${rname//./_} && rname=${rname//\//_} echo "$ttft $cname import" fn=`printf "%s__%s.tf" $ttft $rname` if [ -f "$fn" ] ; then echo "$fn exists already skipping" continue fi printf "resource \"%s\" \"%s\" {}" $ttft $rname > $fn terraform import $ttft.$rname "$cname" | grep Importing terraform state show -no-color $ttft.$rname > t1.txt tfa=`printf "%s.%s" $ttft $rname` terraform show -json | jq --arg myt "$tfa" '.values.root_module.resources[] | select(.address==$myt)' > data/$tfa.json #echo $awsj | jq . rm -f $fn # for k in `cat t1.txt`; do # echo $k # done file="t1.txt" iddo=0 echo $aws2tfmess > $fn while IFS= read line do skip=0 # display $line or do something with $line t1=`echo "$line"` if [[ ${t1} == *"="* ]];then tt1=`echo "$line" | cut -f1 -d'=' | tr -d ' '` tt2=`echo "$line" | cut -f2- -d'='` if [[ ${tt1} == "arn" ]];then skip=1; fi if [[ ${tt1} == "id" ]];then skip=1; fi if [[ ${tt1} == "name" ]];then echo "recovery_window_in_days = 30" >> $fn fi if [[ ${tt1} == "role_arn" ]];then skip=1;fi if [[ ${tt1} == "owner_id" ]];then skip=1;fi if [[ ${tt1} == "resource_owner" ]];then skip=1;fi if [[ ${tt1} == "creation_date" ]];then skip=1;fi if [[ ${tt1} == "rotation_enabled" ]];then skip=1;fi if [[ ${tt1} == "rotation_lambda_arn" ]];then skip=1;fi #if [[ ${tt1} == "availability_zone" ]];then skip=1;fi if [[ ${tt1} == "last_updated_date" ]];then skip=1;fi if [[ ${tt1} == "vpc_id" ]]; then tt2=`echo $tt2 | tr -d '"'` t1=`printf "%s = aws_vpc.%s.id" $tt1 $tt2` fi # rotation rule skip else if [[ "$t1" == *"rotation_rules"* ]]; then #echo $t1 skip=1 lbc=0 rbc=0 breq=0 dover=1 while [[ $breq -eq 0 ]]; do if [[ "${t1}" == *"{"* ]]; then lbc=$(expr $lbc + 1); fi if [[ "${t1}" == *"}"* ]]; then rbc=$(expr $rbc + 1); fi #echo "op=$lbc $rbc $t1" if [[ $rbc -eq $lbc ]]; then breq=1 else read line t1=$(echo "$line") fi done fi fi if [ "$skip" == "0" ]; then #echo $skip $t1 echo "$t1" >> $fn fi done <"$file" ../../scripts/get-secret-version.sh $cname #../../scripts/get-secret-rotation.sh $cname done fi done rm -f t*.txt