Error: constructing secrets manager of type "passphrase": passphrase must be set with PULUMI_CONFIG_PASSPHRASE
Fixes Pulumi refusing to read stack outputs or run commands on a passphrase-encrypted stack without the passphrase. For engineers hitting the secrets-manager construction error on read-only commands, with the env vars that silence it.
Error: constructing secrets manager of type "passphrase": passphrase must be set with PULUMICONFIGPASSPHRASE
TL;DR
The stack encrypts secrets with a passphrase and Pulumi needs it to do anything with state. Set PULUMI_CONFIG_PASSPHRASE (or PULUMI_CONFIG_PASSPHRASE_FILE) in your environment and retry. Newer CLI versions no longer demand it for read-only commands that do not show secrets.
The error
error: constructing secrets manager of type "passphrase": passphrase must be set with PULUMI_CONFIG_PASSPHRASE or PULUMI_CONFIG_PASSPHRASE_FILE environment variablesFix it
Set the passphrase:
export PULUMI_CONFIG_PASSPHRASE='[your passphrase]'(or pointPULUMI_CONFIG_PASSPHRASE_FILEat a file containing it).- Success check:
pulumi stack output [name]prints the value instead of erroring.
- Success check:
If you only need non-secret outputs, upgrade the CLI: recent versions mask secrets as
[secret]instead of demanding the passphrase forpulumi stack outputwithout--show-secrets.- Success check:
pulumi stack outputworks with the passphrase unset; secrets show as[secret].
- Success check:
--show-secretsstill requires the real passphrase. There is no way around that; it is the decryption key.- Success check: with the passphrase set,
pulumi stack output [secret] --show-secretsreveals the value.
- Success check: with the passphrase set,
When to use this
You hit this on a passphrase-encrypted stack (usually a self-managed backend) when running pulumi stack output, pulumi about, or any state-touching command without the passphrase in the environment.
When NOT to use this
Do not use this for KMS-backed stacks (awskms://...) failing with the same text. That is a different problem: the local stack file lost its KMS metadata and Pulumi fell back to passphrase mode.
Compatibility
Pulumi CLI 3.x. The blinding-provider behavior for read-only commands landed in recent 3.x releases.
Variants
error: getting stack configuration: get stack secrets manager: passphrase must be set with PULUMI_CONFIG_PASSPHRASE or PULUMI_CONFIG_PASSPHRASE_FILE environment variablesEnter your passphrase to unlock config/secrets (set PULUMI_CONFIG_PASSPHRASE or PULUMI_CONFIG_PASSPHRASE_FILE to remember):
Root cause
Passphrase encryption derives the state key from your passphrase. Without it in the environment, the CLI cannot construct the secrets manager, and (on older CLIs) even read-only commands failed because they decrypted every secret eagerly.
Edge cases
- A wrong passphrase on
stack export --show-secretscan silently emit nulls for secrets instead of erroring. Verify the passphrase by decrypting one known secret before trusting an export. - CI shells do not inherit your local env. Set the variable (or file) in the pipeline, not just locally.