# ClusterSecret

> Resource ClusterSecret in pulumi-buildkite.

<!-- Generated from the pulumi-buildkite SDK. -->

Resource ClusterSecret in pulumi-buildkite.

Pulumi type: `buildkite:index/clusterSecret:ClusterSecret`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as buildkite from "pulumi-buildkite"

const resource = new buildkite.ClusterSecret("clusterSecret", {
  clusterId: "<clusterId>",
  key: "<key>",
})
```

## Arguments

| Property         | Type     | Required | Description                                                                                                                                                                                                                                                                                                                                  |
| ---------------- | -------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `clusterId`      | `string` | yes      | The UUID of the cluster this secret belongs to.                                                                                                                                                                                                                                                                                              |
| `description`    | `string` | no       | A description of what this secret is for.                                                                                                                                                                                                                                                                                                    |
| `key`            | `string` | yes      | The key name for the secret. Must start with a letter and only contain letters, numbers, and underscores. Maximum 255 characters. Must not start with `buildkite` or `bk` (case-insensitive) as these prefixes are reserved.                                                                                                                 |
| `policy`         | `string` | no       | YAML access policy defining which pipelines and branches can access this secret.                                                                                                                                                                                                                                                             |
| `value`          | `string` | no       | The secret value. Must be less than 8KB. Exactly one of `value` or `valueWo` must be configured. This value is stored in Terraform state; use `valueWo` with `valueWoVersion` to avoid storing secret values in state.                                                                                                                       |
| `valueWo`        | `string` | no       | **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. Write-only secret value. Must be less than 8KB. Exactly one of `value` or `valueWo` must be configured. This value is not stored in Terraform plan or state artifacts. Pair with `valueWoVersion` to trigger secret value updates. |
| `valueWoVersion` | `string` | no       | Non-empty, non-secret version identifier for `valueWo`. Required when `valueWo` is configured. Change this value when the write-only secret value changes, for example by using an external secret manager version ID.                                                                                                                       |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property         | Type     | Computed | Description                                                                                                                                                                                                                                                                                                                                  |
| ---------------- | -------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `clusterId`      | `string` | no       | The UUID of the cluster this secret belongs to.                                                                                                                                                                                                                                                                                              |
| `createdAt`      | `string` | yes      | The time when the secret was created.                                                                                                                                                                                                                                                                                                        |
| `description`    | `string` | no       | A description of what this secret is for.                                                                                                                                                                                                                                                                                                    |
| `key`            | `string` | no       | The key name for the secret. Must start with a letter and only contain letters, numbers, and underscores. Maximum 255 characters. Must not start with `buildkite` or `bk` (case-insensitive) as these prefixes are reserved.                                                                                                                 |
| `policy`         | `string` | no       | YAML access policy defining which pipelines and branches can access this secret.                                                                                                                                                                                                                                                             |
| `updatedAt`      | `string` | yes      | The time when the secret was last updated.                                                                                                                                                                                                                                                                                                   |
| `value`          | `string` | no       | The secret value. Must be less than 8KB. Exactly one of `value` or `valueWo` must be configured. This value is stored in Terraform state; use `valueWo` with `valueWoVersion` to avoid storing secret values in state.                                                                                                                       |
| `valueWo`        | `string` | no       | **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. Write-only secret value. Must be less than 8KB. Exactly one of `value` or `valueWo` must be configured. This value is not stored in Terraform plan or state artifacts. Pair with `valueWoVersion` to trigger secret value updates. |
| `valueWoVersion` | `string` | no       | Non-empty, non-secret version identifier for `valueWo`. Required when `valueWo` is configured. Change this value when the write-only secret value changes, for example by using an external secret manager version ID.                                                                                                                       |
