Prompt: Enter your passphrase to unlock config/secrets on every Pulumi command
Fixes Pulumi prompting for a passphrase on every command when PULUMI_CONFIG_PASSPHRASE is unset. For engineers on passphrase-encrypted stacks who want the prompt gone in interactive and CI use.
Prompt: Enter your passphrase to unlock config/secrets (set PULUMICONFIGPASSPHRASE or PULUMICONFIGPASSPHRASE_FILE to remember)
TL;DR
This is a prompt, not an error. Your stack encrypts secrets with a passphrase. Export PULUMI_CONFIG_PASSPHRASE (or use the _FILE variant) so Pulumi stops asking, or upgrade the CLI so read-only commands no longer need it.
The prompt
Enter your passphrase to unlock config/secrets
(set PULUMI_CONFIG_PASSPHRASE or PULUMI_CONFIG_PASSPHRASE_FILE to remember):Fix it
For the current shell:
export PULUMI_CONFIG_PASSPHRASE='[your passphrase]'.- Success check: the next
pulumicommand runs without prompting.
- Success check: the next
For persistence without the value in shell history, write the passphrase to a file and
export PULUMI_CONFIG_PASSPHRASE_FILE=[path].- Success check: new shells pick it up from your profile.
In CI, store the passphrase as a secret env var on the job and export it before any Pulumi step. Never commit it.
- Success check: unattended runs never block on the prompt.
If you only run read-only commands (
stack outputwithout--show-secrets,about), upgrade the CLI: recent versions mask secrets as[secret]instead of prompting.- Success check: those commands work with no passphrase set.
When to use this
You see this prompt on every Pulumi command for a passphrase-encrypted stack and want it gone.
When NOT to use this
Do not set a different passphrase than the stack was created with. That fails with "passphrase must be the same as the last time the stack was updated", which is a different problem.
Compatibility
Pulumi CLI 3.x, passphrase secrets provider.
Variants
Enter your passphrase to protect config/secrets:(atpulumi stack inittime, when choosing the passphrase)Re-enter your passphrase to confirm:(the confirmation half of the same flow)
Root cause
Passphrase-encrypted stacks need the passphrase to derive the data key for any state access. Without it in the environment, the CLI prompts interactively, which hangs CI and annoys humans.
Edge cases
- Typing the passphrase at the prompt works, but every new shell asks again. The env var is the durable fix.
--show-secretsalways needs the real passphrase, even on new CLIs. There is no read-only bypass for revealing secrets.