Home / Companies / Pulumi / Blog / Post Details
Content Deep Dive

Peace of Mind with Cloud Secret Providers

Blog post from Pulumi

Post Details
Company
Date Published
Author
Lee Briggs
Word Count
3,525
Company Posts That Month
9
Language
English
Hacker News Points
-
Post removed?
No
Summary

Pulumi has enhanced its secret management capabilities to support "Cloud Secret Providers," allowing users to maintain exclusive access to their sensitive data when provisioning infrastructure. Initially, Pulumi offered secret encryption via passphrase or its service backend, but these options lacked the control users desired. Now, Pulumi integrates with several encryption services, including AWS KMS, Azure KeyVault, Google Cloud KMS, and HashiCorp Vault. The article provides a detailed example of utilizing AWS KMS to encrypt secret values in a Pulumi stack, including setting up a KMS key, configuring IAM roles, and ensuring secure access through key policies. It demonstrates how to verify encryption by attempting Pulumi operations without access to the KMS key and explains how to manage Pulumi state files to ensure data remains encrypted. This approach not only strengthens security but also aims to facilitate compliance audits by ensuring that sensitive values are securely encrypted and accessible only to authorized users.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 10 249 47 26 -40%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.