AWS::SecretsManager::SecretCreates a new secret. A *secret* can be a password, a set of credentials such as a user name and password, an OAuth token, or other secret information that you store in an encrypted form in Secrets Manager. For RDS master user credentials, see [AWS::RDS::DBCluster MasterUserSecret](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-rds-dbcluster-masterusersecret.html). For RS admin user credentials, see [AWS::Redshift::Cluster](https://docs.aws.amazon.com/AWSCloud...
8 configurable properties. Click a row to see details.
| Property | Type | Flags |
|---|---|---|
Description | string | |
GenerateSecretString | GenerateSecretString | Write-only |
KmsKeyId | string | |
Name | string | Create-only |
ReplicaRegions | Array<ReplicaRegion> | |
SecretString | string | Write-only |
Tags | Array<Tag> | |
Type | string |
Values returned after the resource is created. Access these with Fn::GetAtt.
| Attribute | Type | Description |
|---|---|---|
Id | string | - |
A minimal template with required properties and common optional ones.
AWSTemplateFormatVersion: "2010-09-09"
Description: Sample template for AWS::SecretsManager::Secret
Resources:
MyResource:
Type: AWS::SecretsManager::Secret
Properties:
Tags:
- Key: Environment
Value: Production
Description: !Ref "AWS::StackName"
Name: !Ref "AWS::StackName"Permissions CloudFormation needs in your IAM role to manage this resource.
secretsmanager:DescribeSecretsecretsmanager:GetRandomPasswordsecretsmanager:CreateSecretsecretsmanager:TagResourcesecretsmanager:ReplicateSecretToRegionssecretsmanager:DeleteSecretsecretsmanager:DescribeSecretsecretsmanager:RemoveRegionsFromReplicationsecretsmanager:ListSecretssecretsmanager:DescribeSecretsecretsmanager:GetSecretValuesecretsmanager:UpdateSecretsecretsmanager:TagResourcesecretsmanager:UntagResourcesecretsmanager:GetRandomPasswordsecretsmanager:GetSecretValuesecretsmanager:ReplicateSecretToRegionssecretsmanager:RemoveRegionsFromReplicationOur bi-weekly newsletter teaches hands-on AWS fundamentals. No certification fluff - just practical knowledge.
Subscribe to NewsletterIdThese properties cannot be changed after the resource is created. Updating them triggers a replacement.
Name