# IntegrationAwsSecretsManager

> Resource IntegrationAwsSecretsManager in pulumi-infisical.

<!-- Generated from the pulumi-infisical SDK. -->

Resource IntegrationAwsSecretsManager in pulumi-infisical.

Pulumi type: `infisical:index/integrationAwsSecretsManager:IntegrationAwsSecretsManager`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as infisical from "pulumi-infisical"

const resource = new infisical.IntegrationAwsSecretsManager(
  "integrationAwsSecretsManager",
  {
    awsRegion: "<awsRegion>",
    environment: "<environment>",
    projectId: "<projectId>",
    secretPath: "<secretPath>",
  },
)
```

## Arguments

| Property             | Type                                          | Required | Description                                                                                                                                                                                                          |
| -------------------- | --------------------------------------------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `accessKeyId`        | `string`                                      | no       | The AWS access key ID. Used to authenticate with AWS Secrets Manager. You must either set `secretAccessKey` and access_key_id, or set `assumeRoleArn` to assume a role.                                              |
| `assumeRoleArn`      | `string`                                      | no       | The ARN of the role to assume when syncing secrets to AWS Secrets Manager. You must either set `secretAccessKey` and access_key_id, or set `assumeRoleArn` to assume a role.                                         |
| `awsRegion`          | `string`                                      | yes      | The AWS region to sync secrets to. (us-east-1, us-east-2, etc)                                                                                                                                                       |
| `environment`        | `string`                                      | yes      | The slug of the environment to sync to AWS Secrets Manager (prod, dev, staging, etc).                                                                                                                                |
| `mappingBehavior`    | `string`                                      | no       | The behavior of the mapping. Can be 'many-to-one' or 'one-to-one'. Many to One: All Infisical secrets will be mapped to a single AWS secret. One to One: Each Infisical secret will be mapped to its own AWS secret. |
| `options`            | `IntegrationAwsSecretsManagerOptions (input)` | no       | Integration options                                                                                                                                                                                                  |
| `projectId`          | `string`                                      | yes      | The ID of your Infisical project.                                                                                                                                                                                    |
| `secretAccessKey`    | `string`                                      | no       | The AWS secret access key. Used to authenticate with AWS Secrets Manager. You must either set `secretAccessKey` and access_key_id, or set `assumeRoleArn` to assume a role.                                          |
| `secretPath`         | `string`                                      | yes      | The secret path in Infisical to sync secrets from.                                                                                                                                                                   |
| `secretsManagerPath` | `string`                                      | no       | The path in AWS Secrets Manager to sync secrets to. This is required if `mappingBehavior` is 'many-to-one'.                                                                                                          |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property             | Type                                           | Computed | Description                                                                                                                                                                                                          |
| -------------------- | ---------------------------------------------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `accessKeyId`        | `string`                                       | no       | The AWS access key ID. Used to authenticate with AWS Secrets Manager. You must either set `secretAccessKey` and access_key_id, or set `assumeRoleArn` to assume a role.                                              |
| `assumeRoleArn`      | `string`                                       | no       | The ARN of the role to assume when syncing secrets to AWS Secrets Manager. You must either set `secretAccessKey` and access_key_id, or set `assumeRoleArn` to assume a role.                                         |
| `awsRegion`          | `string`                                       | no       | The AWS region to sync secrets to. (us-east-1, us-east-2, etc)                                                                                                                                                       |
| `environment`        | `string`                                       | no       | The slug of the environment to sync to AWS Secrets Manager (prod, dev, staging, etc).                                                                                                                                |
| `integrationAuthId`  | `string`                                       | yes      | The ID of the integration auth, used internally by Infisical.                                                                                                                                                        |
| `integrationId`      | `string`                                       | yes      | The ID of the integration, used internally by Infisical.                                                                                                                                                             |
| `mappingBehavior`    | `string`                                       | no       | The behavior of the mapping. Can be 'many-to-one' or 'one-to-one'. Many to One: All Infisical secrets will be mapped to a single AWS secret. One to One: Each Infisical secret will be mapped to its own AWS secret. |
| `options`            | `IntegrationAwsSecretsManagerOptions (output)` | no       | Integration options                                                                                                                                                                                                  |
| `projectId`          | `string`                                       | no       | The ID of your Infisical project.                                                                                                                                                                                    |
| `secretAccessKey`    | `string`                                       | no       | The AWS secret access key. Used to authenticate with AWS Secrets Manager. You must either set `secretAccessKey` and access_key_id, or set `assumeRoleArn` to assume a role.                                          |
| `secretPath`         | `string`                                       | no       | The secret path in Infisical to sync secrets from.                                                                                                                                                                   |
| `secretsManagerPath` | `string`                                       | no       | The path in AWS Secrets Manager to sync secrets to. This is required if `mappingBehavior` is 'many-to-one'.                                                                                                          |

## `IntegrationAwsSecretsManagerOptions (input)`

Input object `IntegrationAwsSecretsManagerOptions`. Fields below belong to this object, not to the parent.

| Property           | Type                                                  | Required | Description                                                                                                                                                                                                                                                                                                           |
| ------------------ | ----------------------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `awsTags`          | `IntegrationAwsSecretsManagerOptionsAwsTag (input)[]` | no       | Tags to attach to the AWS Secrets Manager secrets.                                                                                                                                                                                                                                                                    |
| `metadataSyncMode` | `string`                                              | no       | The sync mode for AWS tags. The supported options are `secret-metadata` and `custom`. If `secret-metadata` is selected, the metadata of the Infisical secrets are used as tags in AWS (only supported for one-to-one integrations). If `custom` is selected, then the key/value pairs in the `awsTags` field is used. |
| `secretPrefix`     | `string`                                              | no       | The prefix to add to the secret name in AWS Secrets Manager.                                                                                                                                                                                                                                                          |

## `IntegrationAwsSecretsManagerOptionsAwsTag (input)`

Input object `IntegrationAwsSecretsManagerOptionsAwsTag`. Fields below belong to this object, not to the parent.

| Property | Type     | Required | Description           |
| -------- | -------- | -------- | --------------------- |
| `key`    | `string` | no       | The key of the tag.   |
| `value`  | `string` | no       | The value of the tag. |

## `IntegrationAwsSecretsManagerOptions (output)`

Output object `IntegrationAwsSecretsManagerOptions`. Fields below belong to this object.

| Property           | Type                                                   | Always present | Description                                                                                                                                                                                                                                                                                                           |
| ------------------ | ------------------------------------------------------ | -------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `awsTags`          | `IntegrationAwsSecretsManagerOptionsAwsTag (output)[]` | no             | Tags to attach to the AWS Secrets Manager secrets.                                                                                                                                                                                                                                                                    |
| `metadataSyncMode` | `string`                                               | no             | The sync mode for AWS tags. The supported options are `secret-metadata` and `custom`. If `secret-metadata` is selected, the metadata of the Infisical secrets are used as tags in AWS (only supported for one-to-one integrations). If `custom` is selected, then the key/value pairs in the `awsTags` field is used. |
| `secretPrefix`     | `string`                                               | no             | The prefix to add to the secret name in AWS Secrets Manager.                                                                                                                                                                                                                                                          |

## `IntegrationAwsSecretsManagerOptionsAwsTag (output)`

Output object `IntegrationAwsSecretsManagerOptionsAwsTag`. Fields below belong to this object.

| Property | Type     | Always present | Description           |
| -------- | -------- | -------------- | --------------------- |
| `key`    | `string` | no             | The key of the tag.   |
| `value`  | `string` | no             | The value of the tag. |
