AWS Secrets Manager: ResourceNotFoundException"
Fixes AWS Secrets Manager ResourceNotFoundException: find whether the secret is misnamed, in another region, or deleted. Use when get or describe calls report the secret missing. Not for access-denied errors.
TL;DR
ResourceNotFoundException means the secret does not exist under that name in that region for that account. Check the name or ARN, the region, and whether it was deleted (pending-deletion secrets are invisible to get calls).
Error
"AWS Secrets Manager: ResourceNotFoundException"Steps
- Re-run the call with an explicit region matching where the secret was created. Expected: either it works or you confirm the region is wrong.
- List secrets and compare names exactly, including any random suffix Secrets Manager appends. Expected: you spot a naming mismatch.
- If you used a partial ARN, use the full ARN or the exact name. Expected: ARN-based lookup is unambiguous.
- Check for pending deletion: deleted secrets stay recoverable for the recovery window but are not readable. Expected: you learn whether it was deleted and when it becomes unrecoverable.
- If it was deleted in error, restore it within the recovery window. Expected: the secret is readable again.
When to use
get-secret-value,describe-secret, or rotation calls report not found.- After renames, region moves, or cleanup scripts.
When not to use
AccessDeniedException(permission problem, not a missing secret).DecryptionFailure(KMS problem).
Tool compatibility
- AWS Secrets Manager; CLI and SDK behave the same.
Variant phrasings
secrets manager can't find the specified secret
Same error family.
secret not found after rotation
The rotation may have created a new version under a staged label; check versions.
Why it happens
Names are region-scoped, partial ARNs are ambiguous, and deletion is soft for the recovery window, all of which make a secret look missing.
Edge cases
- Terraform or CloudFormation renames create a new secret and delete the old; update references.
- Replication across regions is not automatic; a secret in one region does not exist in another.
- Version stages matter: the AWSCURRENT label may point at a version you did not expect.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst4tIJzbrAvzvhPkD8bQ0ZQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.