functualize-secrets-aws
AWS Secrets Manager (aws-sm) and SSM Parameter Store (aws-ssm) providers
for functualize's remote configuration layer.
[database]
password = "aws-sm://prod/db-password"
replica = "aws-sm://prod/db?account=123456789012®ion=eu-west-1"
api_url = "aws-ssm:///prod/api-url"
token = "aws-ssm:///prod/api-token?role=arn:aws:iam::123456789012:role/Deploy"
Values are fetched by func builtin vault sync and stored in the project's
encrypted local vault. Job execution reads the vault, never the network
(ADR-016).
Override keys
| Key | Meaning |
|---|---|
profile |
Named profile from the shared AWS config; replaces the ambient chain for this value. |
role |
IAM role ARN to assume. Composes with profile, which supplies the source identity. |
region |
Region the client is built for. |
account |
Assertion, not a selector: the resolved caller identity must match, or the fetch fails. |
An unknown key is an error, not a no-op — ?porfile=prod must not resolve
quietly under the default identity.
Temporary credentials from role live in memory for the life of the process.
They are never written to disk and never enter the vault, which holds resolved
values, not credentials.
Testing against a local emulator
Set AWS_ENDPOINT_URL and any LocalStack-compatible emulator works:
docker run -d --name floci -p 4566:4566 floci/floci:latest
AWS_ENDPOINT_URL=http://localhost:4566 uv run pytest plugins/credentials/functualize-secrets-aws
Without it the integration tests skip.
Metadata
Release files for functualize-secrets-aws 0.4.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| functualize_secrets_aws-0.4.0.tar.gz | 23.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| functualize_secrets_aws-0.4.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 38.5 kB
Release files / functualize_secrets_aws-0.4.0.tar.gz
| Download URL | functualize_secrets_aws-0.4.0.tar.gz |
|---|---|
| Size | 23.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
4a924ce0697f58c849e5348c0895f4b0581793a54577e2d04832a06437cf0d67
|
|
BLAKE2b-256 checksum How to use checksums |
373b45e833be7546d4c06ac423cba8b812879ddcc29a5df16228b74bc50a86f4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.13
|
Release files / functualize_secrets_aws-0.4.0-py3-none-any.whl
| Download URL | functualize_secrets_aws-0.4.0-py3-none-any.whl |
|---|---|
| Size | 15.4 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a18ec325a9772ab24b49fd7a3cfa8f1afc5eaea73b2d784433095b6618d85d0e
|
|
BLAKE2b-256 checksum How to use checksums |
a3e47c6bc44bb09431420215ce28b3a638dde137dca4e0f231a7fd97eb59dfe8
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.13.13
|