Backup Vault
Encrypted destination for AWS Backup recovery points.
Configuration
Section titled “Configuration”| Setting | Type | Required | Default |
|---|---|---|---|
| Vault name | Text | Yes | — |
| KMS key ARN | Text | — | — |
| Min retention (days) | Number | — | 7 |
| Max retention (days) | Number | — | 0 |
| Vault lock changeable window (days) Options: Locked immediately, 3 days, 7 days, 30 days | Choice | — | 3 |
| Force destroy (delete non-empty) | Toggle | — | false |
| Vault access policy (JSON) | Text | — | — |
| SNS notification events | List | — | — |
| SNS topic ARN | Text | — | — |
| Tags | Key–value | — | — |
Connections
Section titled “Connections”| Socket | Direction | Accepts | Terraform arg |
|---|---|---|---|
| Encryption KMS key | Input | aws.kms-key | kms_key_arn |
| Notification SNS topic | Input | aws.sns | — |
| Backup plans | Output | aws.backup-plan | — |