Password stores a password in AWS Secrets Manager, either from a caller-provided secret value or a generated @pulumi/random password.
Use it when higher-level components need consistent Secrets Manager-backed credential handling instead of plaintext values.
import { Password } from '@studion/infra-code-blocks';
const password = new Password('db-password');
export const secretArn = password.secret.arn;import * as pulumi from '@pulumi/pulumi';
import { Password } from '@studion/infra-code-blocks';
const config = new pulumi.Config();
const password = new Password('db-password', {
value: config.requireSecret('databasePassword'),
});
export const secretName = password.secret.name;- When
args.valueis provided, the component wraps that value withpulumi.secret(...)before exposing it onpassword.value. - When
args.valueis omitted, the component createsrandom.RandomPasswordwithlength: 16,special: true, andoverrideSpecial: '_$'. - The generated Secrets Manager secret uses
namePrefix: ${stack}/${project}/${name}-, so AWS chooses the final suffix. - The Secrets Manager
Secretis exposed aspassword.secretfor callers that need its ARN, name, or other metadata. - The password value is stored in a single
aws.secretsmanager.SecretVersionassecretString; thatSecretVersionis created internally and is not exposed as a component property. - Rotation, password policy customization, and KMS customization are not part of implementation.
Signature
class Password extends pulumi.ComponentResource {
constructor(
name: string,
args?: Password.Args,
opts?: pulumi.ComponentResourceOptions,
);
}Constructor Parameters
| Parameter | Description |
|---|---|
name*string |
Logical Pulumi component name. |
argsPassword.Args |
Optional direct password args object. Default: {}. |
optspulumi.ComponentResourceOptions |
Optional Pulumi component resource options. |
Configuration Options
Direct constructor input: args?: Password.Args
| Property | Description |
|---|---|
valuepulumi.Input<string> |
Explicit password value to store in Secrets Manager. Default: generated random password. |
Outputs
| Property | Description |
|---|---|
namestring |
Component name passed to the constructor. |
valuepulumi.Output<string> |
Primary consumed secret output containing the stored password value. |
secretaws.secretsmanager.Secret |
Underlying AWS Secrets Manager secret for integrations that need the secret ARN, name, or other AWS metadata. |