VectleSkillsError: passphrase must be set with PULUMI_CONFIG_PASSPHRASE (on a KMS-encrypted stack)

Error: passphrase must be set with PULUMI_CONFIG_PASSPHRASE (on a KMS-encrypted stack)

Export

Fixes Pulumi demanding a passphrase on a stack that uses AWS KMS for secrets. For teams on S3 backends whose CI suddenly asks for PULUMI_CONFIG_PASSPHRASE, the cause is the local stack YAML losing its KMS metadata.

Error: passphrase must be set with PULUMICONFIGPASSPHRASE (on a KMS-encrypted stack)

TL;DR

Your stack uses KMS, not a passphrase, but the local Pulumi.[stack].yaml lost its KMS metadata, so Pulumi fell back to passphrase mode. Restore secretsprovider and encryptedkey in the local stack file from pulumi stack export, and stop demanding the passphrase.

The error

error: passphrase must be set with PULUMI_CONFIG_PASSPHRASE

(when the stack is actually configured with awskms://..., not a passphrase)

Fix it

  1. Confirm the stack really uses KMS: pulumi stack export | grep -i secretsprovider should show the awskms:// provider.
  • Success check: you see KMS metadata in the exported state.
  1. Check the local file: open Pulumi.[stack].yaml and look for secretsprovider and encryptedkey.
  • Success check: if they are missing, you found the bug.
  1. Restore them: copy the secretsprovider and encryptedkey values from the stack export into the local YAML (or re-run the stack-select flow that writes them).
  • Success check: pulumi preview no longer asks for a passphrase.
  1. In CI, make this step part of the job: after stack select, ensure the YAML carries the KMS metadata before any Pulumi command runs.
  • Success check: clean-runner builds stop failing on the passphrase prompt.

When to use this

You hit this in CI or on a fresh checkout where the stack was created with --secrets-provider awskms://... but Pulumi now asks for a passphrase.

When NOT to use this

Do not use this for stacks that genuinely use passphrase encryption. There the fix is setting PULUMI_CONFIG_PASSPHRASE, not KMS metadata.

Compatibility

Pulumi CLI 3.x with S3 (or other self-managed) backends and the awskms:// secrets provider.

Variants

  • error: getting stack configuration: get stack secrets manager: passphrase must be set with PULUMI_CONFIG_PASSPHRASE or PULUMI_CONFIG_PASSPHRASE_FILE environment variables on a KMS stack
  • The same fallback after switching Git branches or re-cloning, when the local YAML is regenerated

Root cause

Pulumi reads the secrets provider from two places: the state file and the local stack YAML. Ephemeral CI regenerates the local YAML without the KMS fields, so the CLI defaults to the passphrase provider and demands PULUMI_CONFIG_PASSPHRASE.

Edge cases

  • PULUMI_FALLBACK_TO_STATE_SECRETS_MANAGER=true can paper over this in operator-managed stacks, but fixing the YAML is the real fix.
  • Deleting the local YAML and re-selecting the stack re-triggers the metadata loss. Script the restore instead.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=Error%3A+passphrase+must+be+set+with+PULUMI_CONFIG_PASSPHRASE+%28on+a+KMS-encrypted+stack%29&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.