Tag class

Manages an individual AWS Secrets Manager secret tag. This resource should only be used in cases where AWS Secrets Manager secrets are created outside Terraform (e.g., AWS Secrets Manager secrets managed by other AWS services, such as RDS).

> NOTE: This tagging resource should not be combined with the Terraform resource for managing the parent resource. For example, using aws.secretsmanager.Secret and aws.secretsmanager.Tag to manage tags of the same AWS Secrets Manager secret will cause a perpetual difference where the aws.secretsmanager.Secret resource will try to remove the tag being added by the aws.secretsmanager.Tag resource. However, if the parent resource is created in the same configuration (i.e., if you have no other choice), you should add ignoreChanges = [tags] in the parent resource's lifecycle block. This ensures that Terraform ignores differences in tags managed via the separate tagging resource, avoiding the perpetual difference mentioned above.

> NOTE: This tagging resource does not use the provider ignoreTags configuration.

Example Usage

import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";

const test = new aws.secretsmanager.Secret("test", {name: "example-secret"}, {
    ignoreChanges: ["tags"],
});
const testTag = new aws.secretsmanager.Tag("test", {
    secretId: test.id,
    key: "ExampleKey",
    value: "ExampleValue",
});
import pulumi
import pulumi_aws as aws

test = aws.secretsmanager.Secret("test", name="example-secret",
opts = pulumi.ResourceOptions(ignore_changes=["tags"]))
test_tag = aws.secretsmanager.Tag("test",
    secret_id=test.id,
    key="ExampleKey",
    value="ExampleValue")
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;

return await Deployment.RunAsync(() =>
{
    var test = new Aws.SecretsManager.Secret("test", new()
    {
        Name = "example-secret",
    }, new CustomResourceOptions
    {
        IgnoreChanges =
        {
            "tags",
        },
    });

    var testTag = new Aws.SecretsManager.Tag("test", new()
    {
        SecretId = test.Id,
        Key = "ExampleKey",
        Value = "ExampleValue",
    });

});
package main

import (
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/secretsmanager"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		test, err := secretsmanager.NewSecret(ctx, "test", &secretsmanager.SecretArgs{
			Name: pulumi.String("example-secret"),
		}, pulumi.IgnoreChanges([]string{
			"tags",
		}))
		if err != nil {
			return err
		}
		_, err = secretsmanager.NewTag(ctx, "test", &secretsmanager.TagArgs{
			SecretId: test.ID().ToIDOutput().ToStringOutput(),
			Key:      pulumi.String("ExampleKey"),
			Value:    pulumi.String("ExampleValue"),
		})
		if err != nil {
			return err
		}
		return nil
	})
}
pulumi {
  required_providers {
    aws = {
      source = "pulumi/aws"
    }
  }
}

resource "aws_secretsmanager_secret" "test" {
  lifecycle {
    ignore_changes = [tags]
  }
  name = "example-secret"
}
resource "aws_secretsmanager_tag" "test" {
  secret_id = aws_secretsmanager_secret.test.id
  key       = "ExampleKey"
  value     = "ExampleValue"
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.secretsmanager.Secret;
import com.pulumi.aws.secretsmanager.SecretArgs;
import com.pulumi.aws.secretsmanager.Tag;
import com.pulumi.aws.secretsmanager.TagArgs;
import com.pulumi.resources.CustomResourceOptions;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        var test = new Secret("test", SecretArgs.builder()
            .name("example-secret")
            .build(), CustomResourceOptions.builder()
                .ignoreChanges("tags")
                .build());

        var testTag = new Tag("testTag", TagArgs.builder()
            .secretId(test.id())
            .key("ExampleKey")
            .value("ExampleValue")
            .build());

    }
}
resources:
  test:
    type: aws:secretsmanager:Secret
    properties:
      name: example-secret
    options:
      ignoreChanges:
        - tags
  testTag:
    type: aws:secretsmanager:Tag
    name: test
    properties:
      secretId: ${test.id}
      key: ExampleKey
      value: ExampleValue

Import

Using pulumi import, import aws.secretsmanager.Tag using the AWS Secrets Manager secret identifier and key, separated by a comma (,). For example:

$ pulumi import aws:secretsmanager/tag:Tag example arn:aws:secretsmanager:us-east-1:123456789012:example-secret,ExampleKey

Constructors

Tag(String name, {TagArgs? args, CustomResourceOptions? options})
Creates a new Tag. name The Pulumi resource name. args Arguments used to configure this Tag. The set of arguments for Tag. options Resource options controlling this resource's behavior.
Tag.reference(String urn)
Creates a typed reference to an existing Tag resource.

Properties

childResources → Set<Resource>
finalinherited
completionSources ↔ Map<String, IOutputCompletionSource>
latefinalinherited
hashCode → int
The hash code for this object.
no setterinherited
id ↔ Output<String>
getter/setter pairinherited
isCustom → bool
Returns whether this resource is provider-managed.
no setterinherited
isProtected → bool
Returns whether this resource is protected from deletion.
no setterinherited
isRemote → bool
Whether this resource is registered as remote.
no setterinherited
isResourceReference → bool
Whether this instance represents a resource value returned over RPC.
finalinherited
key ↔ Output<String>
Tag name.
latefinal
region ↔ Output<String>
Region where this resource will be managed. Defaults to the Region set in the provider configuration.
latefinal
resourceTransforms → List<ResourceTransform>
Inherited/explicit async transforms.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
secretId ↔ Output<String>
ID of the AWS Secrets Manager secret to tag.
latefinal
transformations → List<ResourceTransformation>
Inherited/explicit legacy transformations.
no setterinherited
urn ↔ Output<String>
latefinalinherited
value ↔ Output<String>
Tag value.
latefinal

Methods

failId(Object error) → void
Completes this resource ID with an error when registration fails.
inherited
failOutputs(Object error) → void
Completes all output properties with error.
inherited
failUrn(Object error) → void
Completes this resource URN with an error when registration fails.
inherited
getProvider(String moduleMember) → ProviderResource?
Returns provider for moduleMember's package, if configured.
inherited
getResourceName() → String
Returns this resource's logical name.
inherited
getResourceType() → String
Returns this resource's Pulumi type token.
inherited
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
registerOutput<T>(String propertyName, {Object? decoder(Object?)?, bool isSecret = false}) → Output<T>
Registers a dynamic output property for this resource.
inherited
resolveId(String? value, {required bool isKnown}) → void
Resolves the provider-assigned ID for this resource.
inherited
resolveOutputs(Struct outputs) → void
Resolves all output properties from a monitor response payload.
inherited
resolveUrn(String value) → void
Resolves this resource's URN once assigned by the engine.
inherited
serializeProperties(Map<String, dynamic> properties) → Future<Struct>
Serializes resource properties for RPC transmission.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

get(String name, Input<String> id, {TagState? state, CustomResourceOptions? options}) → Tag
Gets an existing Tag resource's state with the given name and id.