# SecretSyncAwsSecretsManager

> Resource SecretSyncAwsSecretsManager in pulumi-infisical.

<!-- Generated from the pulumi-infisical SDK. -->

Resource SecretSyncAwsSecretsManager in pulumi-infisical.

Pulumi type: `infisical:index/secretSyncAwsSecretsManager:SecretSyncAwsSecretsManager`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as infisical from "pulumi-infisical"

const resource = new infisical.SecretSyncAwsSecretsManager(
  "secretSyncAwsSecretsManager",
  {
    connectionId: "<connectionId>",
    destinationConfig: {
      awsRegion: "<awsRegion>",
    },
    environment: "<environment>",
    projectId: "<projectId>",
    secretPath: "<secretPath>",
    syncOptions: {
      initialSyncBehavior: "overwrite-destination",
    },
  },
)
```

## Arguments

| Property            | Type                                                   | Required | Description                                                                                      |
| ------------------- | ------------------------------------------------------ | -------- | ------------------------------------------------------------------------------------------------ |
| `autoSyncEnabled`   | `boolean`                                              | no       | Whether secrets should be automatically synced when changes occur at the source location or not. |
| `connectionId`      | `string`                                               | yes      | The ID of the aws Connection to use for syncing.                                                 |
| `description`       | `string`                                               | no       | An optional description for the AWS Secrets Manager sync.                                        |
| `destinationConfig` | `SecretSyncAwsSecretsManagerDestinationConfig (input)` | yes      | The destination configuration for the secret sync.                                               |
| `environment`       | `string`                                               | yes      | The slug of the project environment to sync secrets from.                                        |
| `name`              | `string`                                               | no       | The name of the AWS Secrets Manager sync to create. Must be slug-friendly.                       |
| `projectId`         | `string`                                               | yes      | The ID of the Infisical project to create the sync in.                                           |
| `secretPath`        | `string`                                               | yes      | The folder path to sync secrets from.                                                            |
| `syncOptions`       | `SecretSyncAwsSecretsManagerSyncOptions (input)`       | yes      | Parameters to modify how secrets are synced.                                                     |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property            | Type                                                    | Computed | Description                                                                                      |
| ------------------- | ------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------ |
| `autoSyncEnabled`   | `boolean`                                               | no       | Whether secrets should be automatically synced when changes occur at the source location or not. |
| `connectionId`      | `string`                                                | no       | The ID of the aws Connection to use for syncing.                                                 |
| `description`       | `string`                                                | no       | An optional description for the AWS Secrets Manager sync.                                        |
| `destinationConfig` | `SecretSyncAwsSecretsManagerDestinationConfig (output)` | no       | The destination configuration for the secret sync.                                               |
| `environment`       | `string`                                                | no       | The slug of the project environment to sync secrets from.                                        |
| `name`              | `string`                                                | no       | The name of the AWS Secrets Manager sync to create. Must be slug-friendly.                       |
| `projectId`         | `string`                                                | no       | The ID of the Infisical project to create the sync in.                                           |
| `secretPath`        | `string`                                                | no       | The folder path to sync secrets from.                                                            |
| `syncOptions`       | `SecretSyncAwsSecretsManagerSyncOptions (output)`       | no       | Parameters to modify how secrets are synced.                                                     |

## `SecretSyncAwsSecretsManagerDestinationConfig (input)`

Input object `SecretSyncAwsSecretsManagerDestinationConfig`. Fields below belong to this object, not to the parent.

| Property                      | Type     | Required | Description                                                                                                                                                                                                          |
| ----------------------------- | -------- | -------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `awsRegion`                   | `string` | yes      | The AWS region of your AWS Secrets Manager                                                                                                                                                                           |
| `awsSecretsManagerSecretName` | `string` | no       | The name of the AWS secret to map to. This only applies when `mappingBehavior` is set to 'many-to-one'.                                                                                                              |
| `mappingBehavior`             | `string` | no       | The behavior of the mapping. Can be 'many-to-one' or 'one-to-one'. Many to One: All Infisical secrets will be mapped to a single AWS secret. One to One: Each Infisical secret will be mapped to its own AWS secret. |

## `SecretSyncAwsSecretsManagerSyncOptions (input)`

Input object `SecretSyncAwsSecretsManagerSyncOptions`. Fields below belong to this object, not to the parent.

| Property                   | Type                                                  | Required | Description                                                                                                                                                                 |
| -------------------------- | ----------------------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `awsKmsKeyId`              | `string`                                              | no       | The AWS KMS key ID to use for encryption                                                                                                                                    |
| `disableSecretDeletion`    | `boolean`                                             | no       | When set to true, Infisical will not remove secrets from AWS Secrets Manager. Enable this option if you intend to manage some secrets manually outside of Infisical.        |
| `initialSyncBehavior`      | `string`                                              | yes      | Specify how Infisical should resolve the initial sync to the destination. Supported options: overwrite-destination, import-prioritize-source, import-prioritize-destination |
| `keySchema`                | `string`                                              | no       | The format to use for structuring secret keys in the AWS Secrets Manager destination.                                                                                       |
| `syncSecretMetadataAsTags` | `boolean`                                             | no       | Whether to sync the secret metadata as tags. This is only supported for the 'one-to-one' mapping behavior.                                                                  |
| `tags`                     | `SecretSyncAwsSecretsManagerSyncOptionsTag (input)[]` | no       | The tags to sync to the secret                                                                                                                                              |

## `SecretSyncAwsSecretsManagerSyncOptionsTag (input)`

Input object `SecretSyncAwsSecretsManagerSyncOptionsTag`. Fields below belong to this object, not to the parent.

| Property | Type     | Required | Description          |
| -------- | -------- | -------- | -------------------- |
| `key`    | `string` | yes      | The key of the tag   |
| `value`  | `string` | yes      | The value of the tag |

## `SecretSyncAwsSecretsManagerDestinationConfig (output)`

Output object `SecretSyncAwsSecretsManagerDestinationConfig`. Fields below belong to this object.

| Property                      | Type     | Always present | Description                                                                                                                                                                                                          |
| ----------------------------- | -------- | -------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `awsRegion`                   | `string` | yes            | The AWS region of your AWS Secrets Manager                                                                                                                                                                           |
| `awsSecretsManagerSecretName` | `string` | no             | The name of the AWS secret to map to. This only applies when `mappingBehavior` is set to 'many-to-one'.                                                                                                              |
| `mappingBehavior`             | `string` | yes            | The behavior of the mapping. Can be 'many-to-one' or 'one-to-one'. Many to One: All Infisical secrets will be mapped to a single AWS secret. One to One: Each Infisical secret will be mapped to its own AWS secret. |

## `SecretSyncAwsSecretsManagerSyncOptions (output)`

Output object `SecretSyncAwsSecretsManagerSyncOptions`. Fields below belong to this object.

| Property                   | Type                                                   | Always present | Description                                                                                                                                                                 |
| -------------------------- | ------------------------------------------------------ | -------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `awsKmsKeyId`              | `string`                                               | no             | The AWS KMS key ID to use for encryption                                                                                                                                    |
| `disableSecretDeletion`    | `boolean`                                              | yes            | When set to true, Infisical will not remove secrets from AWS Secrets Manager. Enable this option if you intend to manage some secrets manually outside of Infisical.        |
| `initialSyncBehavior`      | `string`                                               | yes            | Specify how Infisical should resolve the initial sync to the destination. Supported options: overwrite-destination, import-prioritize-source, import-prioritize-destination |
| `keySchema`                | `string`                                               | no             | The format to use for structuring secret keys in the AWS Secrets Manager destination.                                                                                       |
| `syncSecretMetadataAsTags` | `boolean`                                              | yes            | Whether to sync the secret metadata as tags. This is only supported for the 'one-to-one' mapping behavior.                                                                  |
| `tags`                     | `SecretSyncAwsSecretsManagerSyncOptionsTag (output)[]` | no             | The tags to sync to the secret                                                                                                                                              |

## `SecretSyncAwsSecretsManagerSyncOptionsTag (output)`

Output object `SecretSyncAwsSecretsManagerSyncOptionsTag`. Fields below belong to this object.

| Property | Type     | Always present | Description          |
| -------- | -------- | -------------- | -------------------- |
| `key`    | `string` | yes            | The key of the tag   |
| `value`  | `string` | yes            | The value of the tag |
