HashiCorp Vault v6.4.0 published on Wednesday, Nov 20, 2024 by Pulumi
Pulumi Vault Provider: Installation & Configuration
The Pulumi Vault provider uses the Vault SDK to manage resources.
Installation
The HashiCorp Vault provider is available as a package in all Pulumi languages:
- JavaScript/TypeScript:
@pulumi/vault
- Python:
pulumi-vault
- Go:
github.com/pulumi/pulumi-vault/sdk/v4/go/vault
- .NET:
Pulumi.Vault
- Java:
com.pulumi/vault
Configuration
Pulumi relies on the Vault SDK to authenticate requests from your computer to HashiCorp Vault. Your credentials are never sent to pulumi.com.
Once the credentials are obtained, there are two ways to communicate your configuration tokens to Pulumi:
Set the environment variables
VAULT_ADDR
andVAULT_TOKEN
:$ export VAULT_ADDR=XXXXXX $ export VAULT_TOKEN=YYYYYY
Set them using configuration, if you prefer that they be stored alongside your Pulumi stack for easy multi-user access:
$ pulumi config set vault:address XXXXXX $ pulumi config set vault:token YYYYYY --secret
The complete list of
configuration parameters is in the HashiCorp Vault provider README.
Remember to pass --secret
when setting token
so that it is properly encrypted.