techlite/fetch-gcp-secret

1.0.0

repeating is safe Reads state that changes out there — infrastructure, a remote registry. Repeating causes no effect, but the result may differ, which is why it never comes from cache.

Reads one secret from GCP Secret Manager and returns it as a secret output

task

How to use

oren add techlite/fetch-gcp-secret

↓ Download YAML 5

The fetch-with-a-task pattern, for Google Cloud: the pipeline's later steps receive the payload through a secret output — content that never touches the host's disk, is written redacted in the run state, and is refused by `--resume` (a secret output re-fetches instead of resurrecting).

Byte-exact on purpose: the payload leaves exactly as stored, trailing newline included — an SSH key or a PEM certificate is refused by its consumer over one missing byte.