Skip to main content

IntegrationAwsSecretsManager

Resource IntegrationAwsSecretsManager in pulumi-infisical.
5 min read

Resource IntegrationAwsSecretsManager in pulumi-infisical.

Pulumi type: infisical:index/integrationAwsSecretsManager:IntegrationAwsSecretsManager.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
accessKeyIdstringnoThe AWS access key ID. Used to authenticate with AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role.
assumeRoleArnstringnoThe ARN of the role to assume when syncing secrets to AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role.
awsRegionstringyesThe AWS region to sync secrets to. (us-east-1, us-east-2, etc)
environmentstringyesThe slug of the environment to sync to AWS Secrets Manager (prod, dev, staging, etc).
mappingBehaviorstringnoThe behavior of the mapping. Can be 'many-to-one' or 'one-to-one'. Many to One: All Infisical secrets will be mapped to a single AWS secret. One to One: Each Infisical secret will be mapped to its own AWS secret.
optionsIntegrationAwsSecretsManagerOptions (input)noIntegration options
projectIdstringyesThe ID of your Infisical project.
secretAccessKeystringnoThe AWS secret access key. Used to authenticate with AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role.
secretPathstringyesThe secret path in Infisical to sync secrets from.
secretsManagerPathstringnoThe path in AWS Secrets Manager to sync secrets to. This is required if mappingBehavior is 'many-to-one'.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
accessKeyIdstringnoThe AWS access key ID. Used to authenticate with AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role.
assumeRoleArnstringnoThe ARN of the role to assume when syncing secrets to AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role.
awsRegionstringnoThe AWS region to sync secrets to. (us-east-1, us-east-2, etc)
environmentstringnoThe slug of the environment to sync to AWS Secrets Manager (prod, dev, staging, etc).
integrationAuthIdstringyesThe ID of the integration auth, used internally by Infisical.
integrationIdstringyesThe ID of the integration, used internally by Infisical.
mappingBehaviorstringnoThe behavior of the mapping. Can be 'many-to-one' or 'one-to-one'. Many to One: All Infisical secrets will be mapped to a single AWS secret. One to One: Each Infisical secret will be mapped to its own AWS secret.
optionsIntegrationAwsSecretsManagerOptions (output)noIntegration options
projectIdstringnoThe ID of your Infisical project.
secretAccessKeystringnoThe AWS secret access key. Used to authenticate with AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role.
secretPathstringnoThe secret path in Infisical to sync secrets from.
secretsManagerPathstringnoThe path in AWS Secrets Manager to sync secrets to. This is required if mappingBehavior is 'many-to-one'.

IntegrationAwsSecretsManagerOptions (input)#

Input object IntegrationAwsSecretsManagerOptions. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
awsTagsIntegrationAwsSecretsManagerOptionsAwsTag (input)[]noTags to attach to the AWS Secrets Manager secrets.
metadataSyncModestringnoThe sync mode for AWS tags. The supported options are secret-metadata and custom. If secret-metadata is selected, the metadata of the Infisical secrets are used as tags in AWS (only supported for one-to-one integrations). If custom is selected, then the key/value pairs in the awsTags field is used.
secretPrefixstringnoThe prefix to add to the secret name in AWS Secrets Manager.

IntegrationAwsSecretsManagerOptionsAwsTag (input)#

Input object IntegrationAwsSecretsManagerOptionsAwsTag. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
keystringnoThe key of the tag.
valuestringnoThe value of the tag.

IntegrationAwsSecretsManagerOptions (output)#

Output object IntegrationAwsSecretsManagerOptions. Fields below belong to this object.

PropertyTypeAlways presentDescription
awsTagsIntegrationAwsSecretsManagerOptionsAwsTag (output)[]noTags to attach to the AWS Secrets Manager secrets.
metadataSyncModestringnoThe sync mode for AWS tags. The supported options are secret-metadata and custom. If secret-metadata is selected, the metadata of the Infisical secrets are used as tags in AWS (only supported for one-to-one integrations). If custom is selected, then the key/value pairs in the awsTags field is used.
secretPrefixstringnoThe prefix to add to the secret name in AWS Secrets Manager.

IntegrationAwsSecretsManagerOptionsAwsTag (output)#

Output object IntegrationAwsSecretsManagerOptionsAwsTag. Fields below belong to this object.

PropertyTypeAlways presentDescription
keystringnoThe key of the tag.
valuestringnoThe value of the tag.