Error: passphrase must be set with PULUMI_CONFIG_PASSPHRASE (on a KMS-encrypted stack)
Fixes Pulumi demanding a passphrase on a stack that uses AWS KMS for secrets. For teams on S3 backends whose CI suddenly asks for PULUMI_CONFIG_PASSPHRASE, the cause is the local stack YAML losing its KMS metadata.
Error: passphrase must be set with PULUMICONFIGPASSPHRASE (on a KMS-encrypted stack)
TL;DR
Your stack uses KMS, not a passphrase, but the local Pulumi.[stack].yaml lost its KMS metadata, so Pulumi fell back to passphrase mode. Restore secretsprovider and encryptedkey in the local stack file from pulumi stack export, and stop demanding the passphrase.
The error
error: passphrase must be set with PULUMI_CONFIG_PASSPHRASE(when the stack is actually configured with awskms://..., not a passphrase)
Fix it
Confirm the stack really uses KMS:
pulumi stack export | grep -i secretsprovidershould show theawskms://provider.- Success check: you see KMS metadata in the exported state.
Check the local file: open
Pulumi.[stack].yamland look forsecretsproviderandencryptedkey.- Success check: if they are missing, you found the bug.
Restore them: copy the
secretsproviderandencryptedkeyvalues from the stack export into the local YAML (or re-run the stack-select flow that writes them).- Success check:
pulumi previewno longer asks for a passphrase.
- Success check:
In CI, make this step part of the job: after stack select, ensure the YAML carries the KMS metadata before any Pulumi command runs.
- Success check: clean-runner builds stop failing on the passphrase prompt.
When to use this
You hit this in CI or on a fresh checkout where the stack was created with --secrets-provider awskms://... but Pulumi now asks for a passphrase.
When NOT to use this
Do not use this for stacks that genuinely use passphrase encryption. There the fix is setting PULUMI_CONFIG_PASSPHRASE, not KMS metadata.
Compatibility
Pulumi CLI 3.x with S3 (or other self-managed) backends and the awskms:// secrets provider.
Variants
error: getting stack configuration: get stack secrets manager: passphrase must be set with PULUMI_CONFIG_PASSPHRASE or PULUMI_CONFIG_PASSPHRASE_FILE environment variableson a KMS stack- The same fallback after switching Git branches or re-cloning, when the local YAML is regenerated
Root cause
Pulumi reads the secrets provider from two places: the state file and the local stack YAML. Ephemeral CI regenerates the local YAML without the KMS fields, so the CLI defaults to the passphrase provider and demands PULUMI_CONFIG_PASSPHRASE.
Edge cases
PULUMI_FALLBACK_TO_STATE_SECRETS_MANAGER=truecan paper over this in operator-managed stacks, but fixing the YAML is the real fix.- Deleting the local YAML and re-selecting the stack re-triggers the metadata loss. Script the restore instead.