Resource IntegrationAwsSecretsManager in pulumi-infisical.
Pulumi type: infisical:index/integrationAwsSecretsManager:IntegrationAwsSecretsManager.
name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.
Example#
Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.
Arguments#
| Property | Type | Required | Description |
|---|---|---|---|
accessKeyId | string | no | The AWS access key ID. Used to authenticate with AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role. |
assumeRoleArn | string | no | The ARN of the role to assume when syncing secrets to AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role. |
awsRegion | string | yes | The AWS region to sync secrets to. (us-east-1, us-east-2, etc) |
environment | string | yes | The slug of the environment to sync to AWS Secrets Manager (prod, dev, staging, etc). |
mappingBehavior | string | no | The behavior of the mapping. Can be 'many-to-one' or 'one-to-one'. Many to One: All Infisical secrets will be mapped to a single AWS secret. One to One: Each Infisical secret will be mapped to its own AWS secret. |
options | IntegrationAwsSecretsManagerOptions (input) | no | Integration options |
projectId | string | yes | The ID of your Infisical project. |
secretAccessKey | string | no | The AWS secret access key. Used to authenticate with AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role. |
secretPath | string | yes | The secret path in Infisical to sync secrets from. |
secretsManagerPath | string | no | The path in AWS Secrets Manager to sync secrets to. This is required if mappingBehavior is 'many-to-one'. |
Outputs#
Computed outputs are produced by the provider. They are not constructor arguments.
| Property | Type | Computed | Description |
|---|---|---|---|
accessKeyId | string | no | The AWS access key ID. Used to authenticate with AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role. |
assumeRoleArn | string | no | The ARN of the role to assume when syncing secrets to AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role. |
awsRegion | string | no | The AWS region to sync secrets to. (us-east-1, us-east-2, etc) |
environment | string | no | The slug of the environment to sync to AWS Secrets Manager (prod, dev, staging, etc). |
integrationAuthId | string | yes | The ID of the integration auth, used internally by Infisical. |
integrationId | string | yes | The ID of the integration, used internally by Infisical. |
mappingBehavior | string | no | The behavior of the mapping. Can be 'many-to-one' or 'one-to-one'. Many to One: All Infisical secrets will be mapped to a single AWS secret. One to One: Each Infisical secret will be mapped to its own AWS secret. |
options | IntegrationAwsSecretsManagerOptions (output) | no | Integration options |
projectId | string | no | The ID of your Infisical project. |
secretAccessKey | string | no | The AWS secret access key. Used to authenticate with AWS Secrets Manager. You must either set secretAccessKey and access_key_id, or set assumeRoleArn to assume a role. |
secretPath | string | no | The secret path in Infisical to sync secrets from. |
secretsManagerPath | string | no | The path in AWS Secrets Manager to sync secrets to. This is required if mappingBehavior is 'many-to-one'. |
IntegrationAwsSecretsManagerOptions (input)#
Input object IntegrationAwsSecretsManagerOptions. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
awsTags | IntegrationAwsSecretsManagerOptionsAwsTag (input)[] | no | Tags to attach to the AWS Secrets Manager secrets. |
metadataSyncMode | string | no | The sync mode for AWS tags. The supported options are secret-metadata and custom. If secret-metadata is selected, the metadata of the Infisical secrets are used as tags in AWS (only supported for one-to-one integrations). If custom is selected, then the key/value pairs in the awsTags field is used. |
secretPrefix | string | no | The prefix to add to the secret name in AWS Secrets Manager. |
IntegrationAwsSecretsManagerOptionsAwsTag (input)#
Input object IntegrationAwsSecretsManagerOptionsAwsTag. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
key | string | no | The key of the tag. |
value | string | no | The value of the tag. |
IntegrationAwsSecretsManagerOptions (output)#
Output object IntegrationAwsSecretsManagerOptions. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
awsTags | IntegrationAwsSecretsManagerOptionsAwsTag (output)[] | no | Tags to attach to the AWS Secrets Manager secrets. |
metadataSyncMode | string | no | The sync mode for AWS tags. The supported options are secret-metadata and custom. If secret-metadata is selected, the metadata of the Infisical secrets are used as tags in AWS (only supported for one-to-one integrations). If custom is selected, then the key/value pairs in the awsTags field is used. |
secretPrefix | string | no | The prefix to add to the secret name in AWS Secrets Manager. |
IntegrationAwsSecretsManagerOptionsAwsTag (output)#
Output object IntegrationAwsSecretsManagerOptionsAwsTag. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
key | string | no | The key of the tag. |
value | string | no | The value of the tag. |