.. _amazon.aws.aws_secret_lookup:
*********************
amazon.aws.aws_secret
*********************
**Look up secrets stored in AWS Secrets Manager.**
.. contents::
:local:
:depth: 1
Synopsis
--------
- Look up secrets stored in AWS Secrets Manager provided the caller has the appropriate permissions to read the secret.
- Lookup is based on the secret's *Name* value.
- Optional parameters can be passed into this lookup; *version_id* and *version_stage*
Requirements
------------
The below requirements are needed on the local Ansible controller node that executes this lookup.
- python >= 3.6
- boto3
- botocore >= 1.18.0
Parameters
----------
.. raw:: html
| Parameter |
Choices/Defaults |
Configuration |
Comments |
|
_terms
-
/ required
|
|
|
Name of the secret to look up in AWS Secrets Manager.
|
|
aws_access_key
string
|
|
env:EC2_ACCESS_KEY
env:AWS_ACCESS_KEY
env:AWS_ACCESS_KEY_ID
|
The AWS access key to use.
aliases: aws_access_key_id
|
|
aws_profile
string
|
|
env:AWS_DEFAULT_PROFILE
env:AWS_PROFILE
|
The AWS profile
aliases: boto_profile
|
|
aws_secret_key
string
|
|
env:EC2_SECRET_KEY
env:AWS_SECRET_KEY
env:AWS_SECRET_ACCESS_KEY
|
The AWS secret key that corresponds to the access key.
aliases: aws_secret_access_key
|
|
aws_security_token
string
|
|
env:EC2_SECURITY_TOKEN
env:AWS_SESSION_TOKEN
env:AWS_SECURITY_TOKEN
|
The AWS security token if using temporary access and secret keys.
|
|
bypath
boolean
added in 1.4.0
|
Default:
"no"
|
|
A boolean to indicate whether the parameter is provided as a hierarchy.
|
|
join
boolean
|
Default:
"no"
|
|
Join two or more entries to form an extended secret.
This is useful for overcoming the 4096 character limit imposed by AWS.
No effect when used with bypath.
|
|
nested
boolean
added in 1.4.0
|
Default:
"no"
|
|
A boolean to indicate the secret contains nested values.
|
|
on_deleted
string
added in 2.0.0
|
Choices:
error ←
- skip
- warn
|
|
Action to take if the secret has been marked for deletion.
error will raise a fatal error when the secret has been marked for deletion.
skip will silently ignore the deleted secret.
warn will skip over the deleted secret but issue a warning.
|
|
on_denied
string
|
Choices:
error ←
- skip
- warn
|
|
Action to take if access to the secret is denied.
error will raise a fatal error when access to the secret is denied.
skip will silently ignore the denied secret.
warn will skip over the denied secret but issue a warning.
|
|
on_missing
string
|
Choices:
error ←
- skip
- warn
|
|
Action to take if the secret is missing.
error will raise a fatal error when the secret is missing.
skip will silently ignore the missing secret.
warn will skip over the missing secret but issue a warning.
|
|
region
string
|
|
env:EC2_REGION
env:AWS_REGION
|
The region for which to create the connection.
|
|
version_id
-
|
|
|
Version of the secret(s).
|
|
version_stage
-
|
|
|
Stage of the secret version.
|