GCP.SecretManager reference
AccessSecretVersion
Section titled “AccessSecretVersion”Source:
src/GCP/SecretManager/AccessSecretVersion.ts
Runtime binding for Secret Manager secrets.versions.access.
Bind this operation to a Secret or LocationsSecret in a
Function/Action init phase.
Provide AccessSecretVersionHttp. Payload data is standard
base64.
AccessSecretVersion: Accessing Secret Versions
Section titled “AccessSecretVersion: Accessing Secret Versions”Access the latest version
const access = yield* GCP.SecretManager.AccessSecretVersion(secret);const { payload } = yield* access();Access a specific version
const access = yield* GCP.SecretManager.AccessSecretVersion(secret);const { payload } = yield* access({ version: "1" });AccessSecretVersionHttp
Section titled “AccessSecretVersionHttp”Source:
src/GCP/SecretManager/AccessSecretVersionHttp.tsKind: Layer · Provides:GCP.SecretManager.AccessSecretVersion
HTTP implementation of AccessSecretVersion.
AddSecretVersion
Section titled “AddSecretVersion”Source:
src/GCP/SecretManager/AddSecretVersion.ts
Runtime binding for Secret Manager secrets.addVersion.
Bind this operation to a Secret or LocationsSecret in a
Function/Action init phase.
Provide AddSecretVersionHttp.
AddSecretVersion: Adding Secret Versions
Section titled “AddSecretVersion: Adding Secret Versions”const addVersion = yield* GCP.SecretManager.AddSecretVersion(secret);yield* addVersion({ payload: { data: btoa("hello") } });AddSecretVersionHttp
Section titled “AddSecretVersionHttp”Source:
src/GCP/SecretManager/AddSecretVersionHttp.tsKind: Layer · Provides:GCP.SecretManager.AddSecretVersion
HTTP implementation of AddSecretVersion.
LocationsSecret
Section titled “LocationsSecret”Source:
src/GCP/SecretManager/LocationsSecret.ts
A regional Google Cloud Secret Manager secret. Payloads stay in one
location (projects/{project}/locations/{location}/secrets/{secret}).
For automatically replicated secrets, use Secret.
Changing secretId or location replaces the secret.
LocationsSecret: Creating a LocationsSecret
Section titled “LocationsSecret: Creating a LocationsSecret”Generated name in us-central1
const secret = yield* GCP.SecretManager.LocationsSecret("ApiKey", {});Explicit id, location, labels, and annotations
const secret = yield* GCP.SecretManager.LocationsSecret("ApiKey", { secretId: "order-api-key", location: "us-central1", labels: { env: "prod" }, annotations: { owner: "payments" },});LocationsSecret: Secret Versions
Section titled “LocationsSecret: Secret Versions”const addVersion = yield* GCP.SecretManager.AddSecretVersion(secret);yield* addVersion({ payload: { data: btoa("hello") } });const access = yield* GCP.SecretManager.AccessSecretVersion(secret);const { payload } = yield* access();ReadSecret
Section titled “ReadSecret”Source:
src/GCP/SecretManager/ReadSecret.ts
Read access to a Secret Manager Secret (or regional
LocationsSecret): access, accessBytes. Grants
roles/secretmanager.secretAccessor on the secret only.
ReadSecret: Reading a secret
Section titled “ReadSecret: Reading a secret”Read the latest version
const apiKey = yield* GCP.SecretManager.ReadSecret(secret);const value = yield* apiKey.access();// …provided with Effect.provide(GCP.SecretManager.ReadSecretHttp)Pin a version
const previous = yield* apiKey.access("3");ReadSecretHttp
Section titled “ReadSecretHttp”Source:
src/GCP/SecretManager/ReadSecretHttp.tsKind: Layer · Provides:GCP.SecretManager.ReadSecret
HTTP implementation of ReadSecret over the Secret Manager REST API.
ReadWriteSecret
Section titled “ReadWriteSecret”Source:
src/GCP/SecretManager/ReadWriteSecret.ts
Read and version-management access to a Secret Manager Secret.
No predefined role covers both, so this grants
roles/secretmanager.secretAccessor and
roles/secretmanager.secretVersionManager on the secret only.
ReadWriteSecret: Reading and rotating
Section titled “ReadWriteSecret: Reading and rotating”const apiKey = yield* GCP.SecretManager.ReadWriteSecret(secret);const current = yield* apiKey.access();yield* apiKey.addVersion(rotate(current));// …provided with Effect.provide(GCP.SecretManager.ReadWriteSecretHttp)ReadWriteSecretHttp
Section titled “ReadWriteSecretHttp”Source:
src/GCP/SecretManager/ReadWriteSecretHttp.tsKind: Layer · Provides:GCP.SecretManager.ReadWriteSecret
HTTP implementation of ReadWriteSecret over the Secret Manager REST API.
Secret
Section titled “Secret”Source:
src/GCP/SecretManager/Secret.ts
A Google Cloud Secret Manager secret (metadata and replication). Secret
payloads live on versions — use AddSecretVersion and
AccessSecretVersion to write and read them.
Changing secretId or replication replaces the secret.
Secret: Creating a Secret
Section titled “Secret: Creating a Secret”Generated name
const secret = yield* GCP.SecretManager.Secret("ApiKey", {});Explicit id, labels, and annotations
const secret = yield* GCP.SecretManager.Secret("ApiKey", { secretId: "order-api-key", labels: { env: "prod" }, annotations: { owner: "payments" },});Secret: Replication
Section titled “Secret: Replication”const secret = yield* GCP.SecretManager.Secret("RegionalKey", { replication: { userManaged: { replicas: [{ location: "us-central1" }], }, },});Secret: Secret Versions
Section titled “Secret: Secret Versions”const addVersion = yield* GCP.SecretManager.AddSecretVersion(secret);yield* addVersion({ payload: { data: btoa("hello") } });const access = yield* GCP.SecretManager.AccessSecretVersion(secret);const { payload } = yield* access();WriteSecret
Section titled “WriteSecret”Source:
src/GCP/SecretManager/WriteSecret.ts
Write access to a Secret Manager Secret (or regional
LocationsSecret): addVersion, disableVersion, destroyVersion.
Grants roles/secretmanager.secretVersionManager on the secret only
(secretVersionAdder cannot disable or destroy). It cannot read payloads.
WriteSecret: Rotating a secret
Section titled “WriteSecret: Rotating a secret”const apiKey = yield* GCP.SecretManager.WriteSecret(secret);const version = yield* apiKey.addVersion(newKey);yield* apiKey.destroyVersion(previousVersion);// …provided with Effect.provide(GCP.SecretManager.WriteSecretHttp)WriteSecretHttp
Section titled “WriteSecretHttp”Source:
src/GCP/SecretManager/WriteSecretHttp.tsKind: Layer · Provides:GCP.SecretManager.WriteSecret
HTTP implementation of WriteSecret over the Secret Manager REST API.