Skip to main content

functualize-secrets-aws

AWS Secrets Manager (aws-sm) and SSM Parameter Store (aws-ssm) providers for functualize's remote configuration layer.

[database]
password = "aws-sm://prod/db-password"
replica  = "aws-sm://prod/db?account=123456789012&region=eu-west-1"
api_url  = "aws-ssm:///prod/api-url"
token    = "aws-ssm:///prod/api-token?role=arn:aws:iam::123456789012:role/Deploy"

Values are fetched by func builtin vault sync and stored in the project's encrypted local vault. Job execution reads the vault, never the network (ADR-016).

Override keys

Key Meaning
profile Named profile from the shared AWS config; replaces the ambient chain for this value.
role IAM role ARN to assume. Composes with profile, which supplies the source identity.
region Region the client is built for.
account Assertion, not a selector: the resolved caller identity must match, or the fetch fails.

An unknown key is an error, not a no-op — ?porfile=prod must not resolve quietly under the default identity.

Temporary credentials from role live in memory for the life of the process. They are never written to disk and never enter the vault, which holds resolved values, not credentials.

Testing against a local emulator

Set AWS_ENDPOINT_URL and any LocalStack-compatible emulator works:

docker run -d --name floci -p 4566:4566 floci/floci:latest
AWS_ENDPOINT_URL=http://localhost:4566 uv run pytest plugins/credentials/functualize-secrets-aws

Without it the integration tests skip.

Metadata

Release files for functualize-secrets-aws 0.4.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for functualize-secrets-aws 0.4.0
File Size Uploaded
functualize_secrets_aws-0.4.0.tar.gz 23.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for functualize-secrets-aws 0.4.0
File Interpreter ABI Platform
functualize_secrets_aws-0.4.0-py3-none-any.whl Python 3 none any Details

Total release size: 38.5 kB

Release files / functualize_secrets_aws-0.4.0.tar.gz

Download URL functualize_secrets_aws-0.4.0.tar.gz
Size 23.1 kB
Tags Source
SHA-256 checksum
How to use checksums
4a924ce0697f58c849e5348c0895f4b0581793a54577e2d04832a06437cf0d67
BLAKE2b-256 checksum
How to use checksums
373b45e833be7546d4c06ac423cba8b812879ddcc29a5df16228b74bc50a86f4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.13

Release files / functualize_secrets_aws-0.4.0-py3-none-any.whl

Download URL functualize_secrets_aws-0.4.0-py3-none-any.whl
Size 15.4 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a18ec325a9772ab24b49fd7a3cfa8f1afc5eaea73b2d784433095b6618d85d0e
BLAKE2b-256 checksum
How to use checksums
a3e47c6bc44bb09431420215ce28b3a638dde137dca4e0f231a7fd97eb59dfe8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.13

Release history Release notifications | RSS feed

This release

0.4.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page