techlite/fetch-gcp-secret
1.0.0
repeating is safe Reads state that changes out there — infrastructure, a remote registry. Repeating causes no effect, but the result may differ, which is why it never comes from cache.Reads one secret from GCP Secret Manager and returns it as a secret output
task
How to use
oren add techlite/fetch-gcp-secretThe fetch-with-a-task pattern, for Google Cloud: the pipeline's later steps receive the payload through a secret output — content that never touches the host's disk, is written redacted in the run state, and is refused by `--resume` (a secret output re-fetches instead of resurrecting).
Byte-exact on purpose: the payload leaves exactly as stored, trailing newline included — an SSH key or a PEM certificate is refused by its consumer over one missing byte.
The step the command writes
- id: fetch-gcp-secret
task: techlite/fetch-gcp-secret@^1.0.0
implementation: techlite/fetch-gcp-secret-gcloud
inputs:
secret: ...
dependencies:
gcloudToken: ...What it requires from your environment
This is the floor: every implementation of this task asks for at least this.
| dependency | type | access | privilege |
|---|---|---|---|
gcloudTokenA short-lived access token with secretmanager.versions.access on the secret — `gcloud auth print-access-token` locally, or the runner's identity in CI. | secret | read only | medium |
Inputs
secretstringrequired- The secret's name in Secret Manager.
projectstring- The project holding the secret. Absent, the token's default project rules.
versionstring- A version number, or `latest`. default:
latest
Outputs
What later steps can reference.
valuestringsecret- The secret's payload, byte-exact.
Implementations
gcloud CLI on the official slim image
google/cloud-sdk:slim