Tag class
Manages an individual AWS Secrets Manager secret tag. This resource should only be used in cases where AWS Secrets Manager secrets are created outside Terraform (e.g., AWS Secrets Manager secrets managed by other AWS services, such as RDS).
> NOTE: This tagging resource should not be combined with the Terraform resource for managing the parent resource. For example, using aws.secretsmanager.Secret and aws.secretsmanager.Tag to manage tags of the same AWS Secrets Manager secret will cause a perpetual difference where the aws.secretsmanager.Secret resource will try to remove the tag being added by the aws.secretsmanager.Tag resource. However, if the parent resource is created in the same configuration (i.e., if you have no other choice), you should add ignoreChanges = [tags] in the parent resource's lifecycle block. This ensures that Terraform ignores differences in tags managed via the separate tagging resource, avoiding the perpetual difference mentioned above.
> NOTE: This tagging resource does not use the provider ignoreTags configuration.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";
const test = new aws.secretsmanager.Secret("test", {name: "example-secret"}, {
ignoreChanges: ["tags"],
});
const testTag = new aws.secretsmanager.Tag("test", {
secretId: test.id,
key: "ExampleKey",
value: "ExampleValue",
});
import pulumi
import pulumi_aws as aws
test = aws.secretsmanager.Secret("test", name="example-secret",
opts = pulumi.ResourceOptions(ignore_changes=["tags"]))
test_tag = aws.secretsmanager.Tag("test",
secret_id=test.id,
key="ExampleKey",
value="ExampleValue")
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;
return await Deployment.RunAsync(() =>
{
var test = new Aws.SecretsManager.Secret("test", new()
{
Name = "example-secret",
}, new CustomResourceOptions
{
IgnoreChanges =
{
"tags",
},
});
var testTag = new Aws.SecretsManager.Tag("test", new()
{
SecretId = test.Id,
Key = "ExampleKey",
Value = "ExampleValue",
});
});
package main
import (
"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/secretsmanager"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
test, err := secretsmanager.NewSecret(ctx, "test", &secretsmanager.SecretArgs{
Name: pulumi.String("example-secret"),
}, pulumi.IgnoreChanges([]string{
"tags",
}))
if err != nil {
return err
}
_, err = secretsmanager.NewTag(ctx, "test", &secretsmanager.TagArgs{
SecretId: test.ID().ToIDOutput().ToStringOutput(),
Key: pulumi.String("ExampleKey"),
Value: pulumi.String("ExampleValue"),
})
if err != nil {
return err
}
return nil
})
}
pulumi {
required_providers {
aws = {
source = "pulumi/aws"
}
}
}
resource "aws_secretsmanager_secret" "test" {
lifecycle {
ignore_changes = [tags]
}
name = "example-secret"
}
resource "aws_secretsmanager_tag" "test" {
secret_id = aws_secretsmanager_secret.test.id
key = "ExampleKey"
value = "ExampleValue"
}
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.secretsmanager.Secret;
import com.pulumi.aws.secretsmanager.SecretArgs;
import com.pulumi.aws.secretsmanager.Tag;
import com.pulumi.aws.secretsmanager.TagArgs;
import com.pulumi.resources.CustomResourceOptions;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var test = new Secret("test", SecretArgs.builder()
.name("example-secret")
.build(), CustomResourceOptions.builder()
.ignoreChanges("tags")
.build());
var testTag = new Tag("testTag", TagArgs.builder()
.secretId(test.id())
.key("ExampleKey")
.value("ExampleValue")
.build());
}
}
resources:
test:
type: aws:secretsmanager:Secret
properties:
name: example-secret
options:
ignoreChanges:
- tags
testTag:
type: aws:secretsmanager:Tag
name: test
properties:
secretId: ${test.id}
key: ExampleKey
value: ExampleValue
Import
Using pulumi import, import aws.secretsmanager.Tag using the AWS Secrets Manager secret identifier and key, separated by a comma (,). For example:
$ pulumi import aws:secretsmanager/tag:Tag example arn:aws:secretsmanager:us-east-1:123456789012:example-secret,ExampleKey
Constructors
- Tag(String name, {TagArgs? args, CustomResourceOptions? options})
-
Creates a new Tag.
nameThe Pulumi resource name.argsArguments used to configure this Tag. The set of arguments for Tag.optionsResource options controlling this resource's behavior. - Tag.reference(String urn)
- Creates a typed reference to an existing Tag resource.
Properties
-
childResources
→ Set<
Resource> -
finalinherited
-
completionSources
↔ Map<
String, IOutputCompletionSource> -
latefinalinherited
- hashCode → int
-
The hash code for this object.
no setterinherited
-
id
↔ Output<
String> -
getter/setter pairinherited
- isCustom → bool
-
Returns whether this resource is provider-managed.
no setterinherited
- isProtected → bool
-
Returns whether this resource is protected from deletion.
no setterinherited
- isRemote → bool
-
Whether this resource is registered as remote.
no setterinherited
- isResourceReference → bool
-
Whether this instance represents a resource value returned over RPC.
finalinherited
-
key
↔ Output<
String> -
Tag name.
latefinal
-
region
↔ Output<
String> -
Region where this resource will be managed. Defaults to the Region set in the provider configuration.
latefinal
-
resourceTransforms
→ List<
ResourceTransform> -
Inherited/explicit async transforms.
no setterinherited
- runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
secretId
↔ Output<
String> -
ID of the AWS Secrets Manager secret to tag.
latefinal
-
transformations
→ List<
ResourceTransformation> -
Inherited/explicit legacy transformations.
no setterinherited
-
urn
↔ Output<
String> -
latefinalinherited
-
value
↔ Output<
String> -
Tag value.
latefinal
Methods
-
failId(
Object error) → void -
Completes this resource ID with an error when registration fails.
inherited
-
failOutputs(
Object error) → void -
Completes all output properties with
error.inherited -
failUrn(
Object error) → void -
Completes this resource URN with an error when registration fails.
inherited
-
getProvider(
String moduleMember) → ProviderResource? -
Returns provider for
moduleMember's package, if configured.inherited -
getResourceName(
) → String -
Returns this resource's logical name.
inherited
-
getResourceType(
) → String -
Returns this resource's Pulumi type token.
inherited
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
registerOutput<
T> (String propertyName, {Object? decoder(Object?)?, bool isSecret = false}) → Output< T> -
Registers a dynamic output property for this resource.
inherited
-
resolveId(
String? value, {required bool isKnown}) → void -
Resolves the provider-assigned ID for this resource.
inherited
-
resolveOutputs(
Struct outputs) → void -
Resolves all output properties from a monitor response payload.
inherited
-
resolveUrn(
String value) → void -
Resolves this resource's URN once assigned by the engine.
inherited
-
serializeProperties(
Map< String, dynamic> properties) → Future<Struct> -
Serializes resource properties for RPC transmission.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited