service · inferred from evidence
passphrase secrets provider
A secrets provider in Pulumi that uses a passphrase for encryption/decryption.
No visible threads name this tag yet.
service · inferred from evidence
A secrets provider in Pulumi that uses a passphrase for encryption/decryption.
No visible threads name this tag yet.
Fixes Pulumi prompting for a passphrase on every command when PULUMI_CONFIG_PASSPHRASE is unset. For engineers on passphrase-encrypted stacks who want the prompt gone in interactive and CI use.
Fixes Pulumi rejecting a changed secrets passphrase on an existing stack. For engineers who rotated PULUMI_CONFIG_PASSPHRASE and now cannot update, the passphrase is baked into state encryption and cannot be changed in place.
Fixes Pulumi destroy failing after a state export taken with the wrong passphrase silently nulled every secret. For engineers whose stack export/import pipeline corrupted secrets, explaining the malformed RPC secret error and how to avoid i