Secrets Manager¶
Client¶
AsyncSecretsManagerClient
¶
AsyncSecretsManagerClient(config: AsyncSecretsManagerConfig | None = None, plugins: list[Plugin] | None = None)
Amazon Web Services Secrets Manager provides a service to enable you to store, manage, and retrieve, secrets.
This guide provides descriptions of the Secrets Manager API. For more information about using this service, see the Amazon Web Services Secrets Manager User Guide.
API Version
This version of the Secrets Manager API Reference documents the Secrets Manager API version 2017-10-17.
For a list of endpoints, see Amazon Web Services Secrets Manager endpoints.
Support and Feedback for Amazon Web Services Secrets Manager
We welcome your feedback. Send your comments to awssecretsmanager-feedback@amazon.com, or post your feedback and questions in the Amazon Web Services Secrets Manager Discussion Forum. For more information about the Amazon Web Services Discussion Forums, see Forums Help.
Logging API Requests
Amazon Web Services Secrets Manager supports Amazon Web Services CloudTrail, a service that records Amazon Web Services API calls for your Amazon Web Services account and delivers log files to an Amazon S3 bucket. By using information that's collected by Amazon Web Services CloudTrail, you can determine the requests successfully made to Secrets Manager, who made the request, when it was made, and so on. For more about Amazon Web Services Secrets Manager and support for Amazon Web Services CloudTrail, see Logging Amazon Web Services Secrets Manager Events with Amazon Web Services CloudTrail in the Amazon Web Services Secrets Manager User Guide. To learn more about CloudTrail, including enabling it and find your log files, see the Amazon Web Services CloudTrail User Guide.
Parameters:
| Name | Type | Description | Default |
|---|---|---|---|
config
|
AsyncSecretsManagerConfig | None
|
Optional configuration for the client. Here you can set things like the endpoint for HTTP services or auth credentials. |
None
|
plugins
|
list[Plugin] | None
|
A list of callables applied once to the client's base configuration. Their changes are inherited by every operation invocation. |
None
|
Operations¶
batch_get_secret_valuecancel_rotate_secretcreate_secretdelete_resource_policydelete_secretdescribe_secretget_random_passwordget_resource_policyget_secret_valuelist_secret_version_idslist_secretsput_resource_policyput_secret_valueremove_regions_from_replicationreplicate_secret_to_regionsrestore_secretrotate_secretstop_replication_to_replicatag_resourceuntag_resourceupdate_secretupdate_secret_version_stagevalidate_resource_policy
Configuration¶
AsyncSecretsManagerConfig
dataclass
¶
Bases: AsyncAwsConfig
Secrets Manager configuration (async-resolved).
Attributes¶
auth_scheme_resolver
class-attribute
instance-attribute
¶
An auth scheme resolver that determines the auth scheme for each operation.
auth_schemes
class-attribute
instance-attribute
¶
A map of auth scheme ids to auth schemes.
aws_access_key_id
class-attribute
instance-attribute
¶
aws_access_key_id: str | None = None
The identifier for a secret access key.
aws_credentials_identity_resolver
class-attribute
instance-attribute
¶
aws_credentials_identity_resolver: IdentityResolver[AWSCredentialsIdentity, AWSIdentityProperties] | None = None
Resolves AWS Credentials. Required for operations that use Sigv4 Auth.
aws_secret_access_key
class-attribute
instance-attribute
¶
aws_secret_access_key: str | None = None
A secret access key that can be used to sign requests.
aws_session_token
class-attribute
instance-attribute
¶
aws_session_token: str | None = None
The session token used with temporary AWS credentials.
endpoint_resolver
class-attribute
instance-attribute
¶
The endpoint resolver used to resolve the final endpoint per-operation based on the configuration.
interceptors
class-attribute
instance-attribute
¶
The list of interceptors, which are hooks that are called during the execution of a request.
protocol
class-attribute
instance-attribute
¶
The protocol to serialize and deserialize requests with.
region
class-attribute
instance-attribute
¶
region: str | None = None
The AWS region to connect to. The configured region is used to determine the service endpoint.
sdk_ua_app_id
class-attribute
instance-attribute
¶
sdk_ua_app_id: str | None = None
A unique and opaque application ID that is appended to the User-Agent header.
user_agent_extra
class-attribute
instance-attribute
¶
user_agent_extra: str | None = None
Additional suffix to be added to the User-Agent header.
Methods:¶
resolve
async
classmethod
¶
resolve(*, profile: str | None = None, fs: FileSystem | None = None, config_file_path: str | None = None, credentials_file_path: str | None = None, **overrides: Unpack[_AsyncSecretsManagerConfigOverrides]) -> Self
Resolve config from environment, config files, defaults, and explicit overrides.
Plugin
module-attribute
¶
Plugin: TypeAlias = Callable[[AsyncSecretsManagerConfig], None]
A callable that customizes a client configuration. Service-level plugins are applied once to the base configuration inherited by every operation. Operation-level plugins apply only to a single operation invocation.
Structures¶
APIErrorTypeExternalSecretRotationMetadataItemFilterReplicaRegionTypeReplicationStatusTypeRotationRulesTypeSecretListEntrySecretValueEntrySecretVersionsListEntryTagValidationErrorsEntry
Errors¶
DecryptionFailureEncryptionFailureInternalServiceErrorInvalidNextTokenExceptionInvalidParameterExceptionInvalidRequestExceptionLimitExceededExceptionMalformedPolicyDocumentExceptionPreconditionNotMetExceptionPublicPolicyExceptionResourceExistsExceptionResourceNotFoundExceptionServiceError