Skip to main content
Pulumi logo Pulumi logo
  1. Docs
  2. Secrets & Configuration
  3. Operations

Operations

    Operational guides for running Pulumi ESC day-to-day: reviewing changes to existing environments, rotating credentials, deploying rotation connectors into private networks, and injecting environment values into commands and CI pipelines.

    If you are looking for what ESC is rather than how to run it, start with Concepts. For reference on the YAML syntax that defines an environment, see Environments.

    Working with environments

    • Approvals — require explicit review and sign-off before applying changes to environments.

    To add, read, and organize the secrets inside an environment, see Environments and fn::secret.

    Rotation

    • Rotating secrets — best practices for rotation, and deploying connectors so rotators can reach databases and services in private networks.

    CI/CD

    For continuous integration, the GitHub Actions integration wires ESC short-lived credentials into your workflows. See also the gh-login provider for ESC-issued GitHub App credentials.

      The infrastructure as code platform for any cloud.