Skip to content

GCP.SecretManager reference

Source: src/GCP/SecretManager/AccessSecretVersion.ts

Runtime binding for Secret Manager secrets.versions.access.

Bind this operation to a Secret or LocationsSecret in a Function/Action init phase. Provide AccessSecretVersionHttp. Payload data is standard base64.

AccessSecretVersion: Accessing Secret Versions

Section titled “AccessSecretVersion: Accessing Secret Versions”

Access the latest version

const access = yield* GCP.SecretManager.AccessSecretVersion(secret);
const { payload } = yield* access();

Access a specific version

const access = yield* GCP.SecretManager.AccessSecretVersion(secret);
const { payload } = yield* access({ version: "1" });

Source: src/GCP/SecretManager/AccessSecretVersionHttp.ts Kind: Layer · Provides: GCP.SecretManager.AccessSecretVersion

HTTP implementation of AccessSecretVersion.

Source: src/GCP/SecretManager/AddSecretVersion.ts

Runtime binding for Secret Manager secrets.addVersion.

Bind this operation to a Secret or LocationsSecret in a Function/Action init phase. Provide AddSecretVersionHttp.

const addVersion = yield* GCP.SecretManager.AddSecretVersion(secret);
yield* addVersion({ payload: { data: btoa("hello") } });

Source: src/GCP/SecretManager/AddSecretVersionHttp.ts Kind: Layer · Provides: GCP.SecretManager.AddSecretVersion

HTTP implementation of AddSecretVersion.

Source: src/GCP/SecretManager/LocationsSecret.ts

A regional Google Cloud Secret Manager secret. Payloads stay in one location (projects/{project}/locations/{location}/secrets/{secret}). For automatically replicated secrets, use Secret.

Changing secretId or location replaces the secret.

LocationsSecret: Creating a LocationsSecret

Section titled “LocationsSecret: Creating a LocationsSecret”

Generated name in us-central1

const secret = yield* GCP.SecretManager.LocationsSecret("ApiKey", {});

Explicit id, location, labels, and annotations

const secret = yield* GCP.SecretManager.LocationsSecret("ApiKey", {
secretId: "order-api-key",
location: "us-central1",
labels: { env: "prod" },
annotations: { owner: "payments" },
});
const addVersion = yield* GCP.SecretManager.AddSecretVersion(secret);
yield* addVersion({ payload: { data: btoa("hello") } });
const access = yield* GCP.SecretManager.AccessSecretVersion(secret);
const { payload } = yield* access();

Source: src/GCP/SecretManager/ReadSecret.ts

Read access to a Secret Manager Secret (or regional LocationsSecret): access, accessBytes. Grants roles/secretmanager.secretAccessor on the secret only.

Read the latest version

const apiKey = yield* GCP.SecretManager.ReadSecret(secret);
const value = yield* apiKey.access();
// …provided with Effect.provide(GCP.SecretManager.ReadSecretHttp)

Pin a version

const previous = yield* apiKey.access("3");

Source: src/GCP/SecretManager/ReadSecretHttp.ts Kind: Layer · Provides: GCP.SecretManager.ReadSecret

HTTP implementation of ReadSecret over the Secret Manager REST API.

Source: src/GCP/SecretManager/ReadWriteSecret.ts

Read and version-management access to a Secret Manager Secret. No predefined role covers both, so this grants roles/secretmanager.secretAccessor and roles/secretmanager.secretVersionManager on the secret only.

const apiKey = yield* GCP.SecretManager.ReadWriteSecret(secret);
const current = yield* apiKey.access();
yield* apiKey.addVersion(rotate(current));
// …provided with Effect.provide(GCP.SecretManager.ReadWriteSecretHttp)

Source: src/GCP/SecretManager/ReadWriteSecretHttp.ts Kind: Layer · Provides: GCP.SecretManager.ReadWriteSecret

HTTP implementation of ReadWriteSecret over the Secret Manager REST API.

Source: src/GCP/SecretManager/Secret.ts

A Google Cloud Secret Manager secret (metadata and replication). Secret payloads live on versions — use AddSecretVersion and AccessSecretVersion to write and read them.

Changing secretId or replication replaces the secret.

Generated name

const secret = yield* GCP.SecretManager.Secret("ApiKey", {});

Explicit id, labels, and annotations

const secret = yield* GCP.SecretManager.Secret("ApiKey", {
secretId: "order-api-key",
labels: { env: "prod" },
annotations: { owner: "payments" },
});
const secret = yield* GCP.SecretManager.Secret("RegionalKey", {
replication: {
userManaged: {
replicas: [{ location: "us-central1" }],
},
},
});
const addVersion = yield* GCP.SecretManager.AddSecretVersion(secret);
yield* addVersion({ payload: { data: btoa("hello") } });
const access = yield* GCP.SecretManager.AccessSecretVersion(secret);
const { payload } = yield* access();

Source: src/GCP/SecretManager/WriteSecret.ts

Write access to a Secret Manager Secret (or regional LocationsSecret): addVersion, disableVersion, destroyVersion. Grants roles/secretmanager.secretVersionManager on the secret only (secretVersionAdder cannot disable or destroy). It cannot read payloads.

const apiKey = yield* GCP.SecretManager.WriteSecret(secret);
const version = yield* apiKey.addVersion(newKey);
yield* apiKey.destroyVersion(previousVersion);
// …provided with Effect.provide(GCP.SecretManager.WriteSecretHttp)

Source: src/GCP/SecretManager/WriteSecretHttp.ts Kind: Layer · Provides: GCP.SecretManager.WriteSecret

HTTP implementation of WriteSecret over the Secret Manager REST API.