# Error: passphrase must be set with PULUMI_CONFIG_PASSPHRASE (on a KMS-encrypted stack)

## TL;DR
Your stack uses KMS, not a passphrase, but the local `Pulumi.[stack].yaml` lost its KMS metadata, so Pulumi fell back to passphrase mode. Restore `secretsprovider` and `encryptedkey` in the local stack file from `pulumi stack export`, and stop demanding the passphrase.

## The error

```
error: passphrase must be set with PULUMI_CONFIG_PASSPHRASE
```

(when the stack is actually configured with `awskms://...`, not a passphrase)

## Fix it

1. Confirm the stack really uses KMS: `pulumi stack export | grep -i secretsprovider` should show the `awskms://` provider.
   - Success check: you see KMS metadata in the exported state.
2. Check the local file: open `Pulumi.[stack].yaml` and look for `secretsprovider` and `encryptedkey`.
   - Success check: if they are missing, you found the bug.
3. Restore them: copy the `secretsprovider` and `encryptedkey` values from the stack export into the local YAML (or re-run the stack-select flow that writes them).
   - Success check: `pulumi preview` no longer asks for a passphrase.
4. In CI, make this step part of the job: after stack select, ensure the YAML carries the KMS metadata before any Pulumi command runs.
   - Success check: clean-runner builds stop failing on the passphrase prompt.

## When to use this
You hit this in CI or on a fresh checkout where the stack was created with `--secrets-provider awskms://...` but Pulumi now asks for a passphrase.

## When NOT to use this
Do not use this for stacks that genuinely use passphrase encryption. There the fix is setting `PULUMI_CONFIG_PASSPHRASE`, not KMS metadata.

## Compatibility
Pulumi CLI 3.x with S3 (or other self-managed) backends and the `awskms://` secrets provider.

## Variants
- `error: getting stack configuration: get stack secrets manager: passphrase must be set with PULUMI_CONFIG_PASSPHRASE or PULUMI_CONFIG_PASSPHRASE_FILE environment variables` on a KMS stack
- The same fallback after switching Git branches or re-cloning, when the local YAML is regenerated

## Root cause
Pulumi reads the secrets provider from two places: the state file and the local stack YAML. Ephemeral CI regenerates the local YAML without the KMS fields, so the CLI defaults to the passphrase provider and demands `PULUMI_CONFIG_PASSPHRASE`.

## Edge cases
- `PULUMI_FALLBACK_TO_STATE_SECRETS_MANAGER=true` can paper over this in operator-managed stacks, but fixing the YAML is the real fix.
- Deleting the local YAML and re-selecting the stack re-triggers the metadata loss. Script the restore instead.
