1. Registry
  2. Packages
  3. Alibaba Cloud Provider
  4. API Docs
  5. apig
  6. Secret
Viewing docs for Alibaba Cloud v3.108.0
published on Thursday, Sep 17, 2026 by Pulumi
alicloud logo alicloud logo
Viewing docs for Alibaba Cloud v3.108.0
published on Thursday, Sep 17, 2026 by Pulumi

    Provides a APIG Secret resource.

    API gateway secret.

    For information about APIG Secret and how to use it, see What is Secret.

    NOTE: Available since v1.293.0.

    Example Usage

    Basic Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as alicloud from "@pulumi/alicloud";
    
    const config = new pulumi.Config();
    const name = config.get("name") || "terraform-example";
    const _default = alicloud.vpc.getNetworks({
        nameRegex: "^default-NODELETING$",
    });
    const defaultGetSwitches = _default.then(_default => alicloud.vpc.getSwitches({
        vpcId: _default.ids?.[0],
        zoneId: "cn-hangzhou-j",
    }));
    const defaultInstance = new alicloud.kms.Instance("default", {
        productVersion: "3",
        vpcNum: 1,
        keyNum: 1000,
        secretNum: 1000,
        spec: 1000,
        vpcId: _default.then(_default => _default.ids?.[0]),
        vswitchIds: [defaultGetSwitches.then(defaultGetSwitches => defaultGetSwitches.ids?.[0])],
        zoneIds: [
            "cn-hangzhou-k",
            "cn-hangzhou-j",
        ],
    });
    const defaultKey = new alicloud.kms.Key("default", {
        dkmsInstanceId: defaultInstance.id,
        pendingWindowInDays: 7,
    });
    const defaultSecret = new alicloud.kms.Secret("default", {
        secretData: name,
        secretName: name,
        versionId: "v1",
        dkmsInstanceId: defaultKey.dkmsInstanceId,
        encryptionKeyId: defaultKey.id,
        forceDeleteWithoutRecovery: true,
    });
    const defaultSecret2 = new alicloud.apig.Secret("default", {
        gatewayType: "API",
        name: name,
        secretSource: "KMS",
        secretData: defaultSecret.secretData,
        kmsConfig: {
            kmsInstanceId: defaultSecret.dkmsInstanceId,
            kmsKeyId: defaultSecret.encryptionKeyId,
        },
    });
    
    import pulumi
    import pulumi_alicloud as alicloud
    
    config = pulumi.Config()
    name = config.get("name")
    if name is None:
        name = "terraform-example"
    default = alicloud.vpc.get_networks(name_regex="^default-NODELETING$")
    default_get_switches = alicloud.vpc.get_switches(vpc_id=default.ids[0],
        zone_id="cn-hangzhou-j")
    default_instance = alicloud.kms.Instance("default",
        product_version="3",
        vpc_num=1,
        key_num=1000,
        secret_num=1000,
        spec=1000,
        vpc_id=default.ids[0],
        vswitch_ids=[default_get_switches.ids[0]],
        zone_ids=[
            "cn-hangzhou-k",
            "cn-hangzhou-j",
        ])
    default_key = alicloud.kms.Key("default",
        dkms_instance_id=default_instance.id,
        pending_window_in_days=7)
    default_secret = alicloud.kms.Secret("default",
        secret_data=name,
        secret_name=name,
        version_id="v1",
        dkms_instance_id=default_key.dkms_instance_id,
        encryption_key_id=default_key.id,
        force_delete_without_recovery=True)
    default_secret2 = alicloud.apig.Secret("default",
        gateway_type="API",
        name=name,
        secret_source="KMS",
        secret_data=default_secret.secret_data,
        kms_config={
            "kms_instance_id": default_secret.dkms_instance_id,
            "kms_key_id": default_secret.encryption_key_id,
        })
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-alicloud/sdk/v3/go/alicloud/apig"
    	"github.com/pulumi/pulumi-alicloud/sdk/v3/go/alicloud/kms"
    	"github.com/pulumi/pulumi-alicloud/sdk/v3/go/alicloud/vpc"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi/config"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		cfg := config.New(ctx, "")
    		name := "terraform-example"
    		if param := cfg.Get("name"); param != "" {
    			name = param
    		}
    		_default, err := vpc.GetNetworks(ctx, &vpc.GetNetworksArgs{
    			NameRegex: pulumi.StringRef("^default-NODELETING$"),
    		}, nil)
    		if err != nil {
    			return err
    		}
    		defaultGetSwitches, err := vpc.GetSwitches(ctx, &vpc.GetSwitchesArgs{
    			VpcId:  pulumi.StringRef(_default.Ids[0]),
    			ZoneId: pulumi.StringRef("cn-hangzhou-j"),
    		}, nil)
    		if err != nil {
    			return err
    		}
    		defaultInstance, err := kms.NewInstance(ctx, "default", &kms.InstanceArgs{
    			ProductVersion: pulumi.String("3"),
    			VpcNum:         pulumi.Int(1),
    			KeyNum:         pulumi.Int(1000),
    			SecretNum:      pulumi.Int(1000),
    			Spec:           pulumi.Int(1000),
    			VpcId:          pulumi.String(_default.Ids[0]),
    			VswitchIds: pulumi.StringArray{
    				pulumi.String(defaultGetSwitches.Ids[0]),
    			},
    			ZoneIds: pulumi.StringArray{
    				pulumi.String("cn-hangzhou-k"),
    				pulumi.String("cn-hangzhou-j"),
    			},
    		})
    		if err != nil {
    			return err
    		}
    		defaultKey, err := kms.NewKey(ctx, "default", &kms.KeyArgs{
    			DkmsInstanceId:      defaultInstance.ID().ToIDOutput().ToStringOutput(),
    			PendingWindowInDays: pulumi.Int(7),
    		})
    		if err != nil {
    			return err
    		}
    		defaultSecret, err := kms.NewSecret(ctx, "default", &kms.SecretArgs{
    			SecretData:                 pulumi.String(name),
    			SecretName:                 pulumi.String(name),
    			VersionId:                  pulumi.String("v1"),
    			DkmsInstanceId:             defaultKey.DkmsInstanceId,
    			EncryptionKeyId:            defaultKey.ID().ToIDOutput().ToStringOutput(),
    			ForceDeleteWithoutRecovery: pulumi.Bool(true),
    		})
    		if err != nil {
    			return err
    		}
    		_, err = apig.NewSecret(ctx, "default", &apig.SecretArgs{
    			GatewayType:  pulumi.String("API"),
    			Name:         pulumi.String(name),
    			SecretSource: pulumi.String("KMS"),
    			SecretData:   defaultSecret.SecretData,
    			KmsConfig: &apig.SecretKmsConfigArgs{
    				KmsInstanceId: defaultSecret.DkmsInstanceId,
    				KmsKeyId:      defaultSecret.EncryptionKeyId,
    			},
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using AliCloud = Pulumi.AliCloud;
    
    return await Deployment.RunAsync(() => 
    {
        var config = new Config();
        var name = config.Get("name") ?? "terraform-example";
        var @default = AliCloud.Vpc.GetNetworks.Invoke(new()
        {
            NameRegex = "^default-NODELETING$",
        });
    
        var defaultGetSwitches = AliCloud.Vpc.GetSwitches.Invoke(new()
        {
            VpcId = @default.Apply(getNetworksResult => getNetworksResult.Ids[0]),
            ZoneId = "cn-hangzhou-j",
        });
    
        var defaultInstance = new AliCloud.Kms.Instance("default", new()
        {
            ProductVersion = "3",
            VpcNum = 1,
            KeyNum = 1000,
            SecretNum = 1000,
            Spec = 1000,
            VpcId = @default.Apply(@default => @default.Apply(getNetworksResult => getNetworksResult.Ids[0])),
            VswitchIds = new[]
            {
                defaultGetSwitches.Apply(getSwitchesResult => getSwitchesResult.Ids[0]),
            },
            ZoneIds = new[]
            {
                "cn-hangzhou-k",
                "cn-hangzhou-j",
            },
        });
    
        var defaultKey = new AliCloud.Kms.Key("default", new()
        {
            DkmsInstanceId = defaultInstance.Id,
            PendingWindowInDays = 7,
        });
    
        var defaultSecret = new AliCloud.Kms.Secret("default", new()
        {
            SecretData = name,
            SecretName = name,
            VersionId = "v1",
            DkmsInstanceId = defaultKey.DkmsInstanceId,
            EncryptionKeyId = defaultKey.Id,
            ForceDeleteWithoutRecovery = true,
        });
    
        var defaultSecret2 = new AliCloud.Apig.Secret("default", new()
        {
            GatewayType = "API",
            Name = name,
            SecretSource = "KMS",
            SecretData = defaultSecret.SecretData,
            KmsConfig = new AliCloud.Apig.Inputs.SecretKmsConfigArgs
            {
                KmsInstanceId = defaultSecret.DkmsInstanceId,
                KmsKeyId = defaultSecret.EncryptionKeyId,
            },
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.alicloud.vpc.VpcFunctions;
    import com.pulumi.alicloud.vpc.inputs.GetNetworksArgs;
    import com.pulumi.alicloud.vpc.inputs.GetSwitchesArgs;
    import com.pulumi.alicloud.kms.Instance;
    import com.pulumi.alicloud.kms.InstanceArgs;
    import com.pulumi.alicloud.kms.Key;
    import com.pulumi.alicloud.kms.KeyArgs;
    import com.pulumi.alicloud.apig.inputs.SecretKmsConfigArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            final var config = ctx.config();
            final var name = config.get("name").orElse("terraform-example");
            final var default = VpcFunctions.getNetworks(GetNetworksArgs.builder()
                .nameRegex("^default-NODELETING$")
                .build());
    
            final var defaultGetSwitches = VpcFunctions.getSwitches(GetSwitchesArgs.builder()
                .vpcId(default_.ids()[0])
                .zoneId("cn-hangzhou-j")
                .build());
    
            var defaultInstance = new Instance("defaultInstance", InstanceArgs.builder()
                .productVersion("3")
                .vpcNum(1)
                .keyNum(1000)
                .secretNum(1000)
                .spec(1000)
                .vpcId(default_.ids()[0])
                .vswitchIds(defaultGetSwitches.ids()[0])
                .zoneIds(            
                    "cn-hangzhou-k",
                    "cn-hangzhou-j")
                .build());
    
            var defaultKey = new Key("defaultKey", KeyArgs.builder()
                .dkmsInstanceId(defaultInstance.id())
                .pendingWindowInDays(7)
                .build());
    
            var defaultSecret = new com.pulumi.alicloud.kms.Secret("defaultSecret", com.pulumi.alicloud.kms.SecretArgs.builder()
                .secretData(name)
                .secretName(name)
                .versionId("v1")
                .dkmsInstanceId(defaultKey.dkmsInstanceId())
                .encryptionKeyId(defaultKey.id())
                .forceDeleteWithoutRecovery(true)
                .build());
    
            var defaultSecret2 = new com.pulumi.alicloud.apig.Secret("defaultSecret2", com.pulumi.alicloud.apig.SecretArgs.builder()
                .gatewayType("API")
                .name(name)
                .secretSource("KMS")
                .secretData(defaultSecret.secretData())
                .kmsConfig(SecretKmsConfigArgs.builder()
                    .kmsInstanceId(defaultSecret.dkmsInstanceId())
                    .kmsKeyId(defaultSecret.encryptionKeyId())
                    .build())
                .build());
    
        }
    }
    
    configuration:
      name:
        type: string
        default: terraform-example
    resources:
      defaultInstance:
        type: alicloud:kms:Instance
        name: default
        properties:
          productVersion: '3'
          vpcNum: '1'
          keyNum: '1000'
          secretNum: '1000'
          spec: '1000'
          vpcId: ${default.ids[0]}
          vswitchIds:
            - ${defaultGetSwitches.ids[0]}
          zoneIds:
            - cn-hangzhou-k
            - cn-hangzhou-j
      defaultKey:
        type: alicloud:kms:Key
        name: default
        properties:
          dkmsInstanceId: ${defaultInstance.id}
          pendingWindowInDays: 7
      defaultSecret:
        type: alicloud:kms:Secret
        name: default
        properties:
          secretData: ${name}
          secretName: ${name}
          versionId: v1
          dkmsInstanceId: ${defaultKey.dkmsInstanceId}
          encryptionKeyId: ${defaultKey.id}
          forceDeleteWithoutRecovery: true
      defaultSecret2:
        type: alicloud:apig:Secret
        name: default
        properties:
          gatewayType: API
          name: ${name}
          secretSource: KMS
          secretData: ${defaultSecret.secretData}
          kmsConfig:
            kmsInstanceId: ${defaultSecret.dkmsInstanceId}
            kmsKeyId: ${defaultSecret.encryptionKeyId}
    variables:
      default:
        fn::invoke:
          function: alicloud:vpc:getNetworks
          arguments:
            nameRegex: ^default-NODELETING$
      defaultGetSwitches:
        fn::invoke:
          function: alicloud:vpc:getSwitches
          arguments:
            vpcId: ${default.ids[0]}
            zoneId: cn-hangzhou-j
    
    pulumi {
      required_providers {
        alicloud = {
          source = "pulumi/alicloud"
        }
      }
    }
    
    data "alicloud_vpc_getnetworks" "default" {
      name_regex = "^default-NODELETING$"
    }
    data "alicloud_vpc_getswitches" "defaultGetSwitches" {
      vpc_id  = data.alicloud_vpc_getnetworks.default.ids[0]
      zone_id = "cn-hangzhou-j"
    }
    
    resource "alicloud_kms_instance" "default" {
      product_version = "3"
      vpc_num         = "1"
      key_num         = "1000"
      secret_num      = "1000"
      spec            = "1000"
      vpc_id          = data.alicloud_vpc_getnetworks.default.ids[0]
      vswitch_ids     = [data.alicloud_vpc_getswitches.defaultGetSwitches.ids[0]]
      zone_ids        = ["cn-hangzhou-k", "cn-hangzhou-j"]
    }
    resource "alicloud_kms_key" "default" {
      dkms_instance_id       = alicloud_kms_instance.default.id
      pending_window_in_days = 7
    }
    resource "alicloud_kms_secret" "default" {
      secret_data                   = var.name
      secret_name                   = var.name
      version_id                    = "v1"
      dkms_instance_id              = alicloud_kms_key.default.dkms_instance_id
      encryption_key_id             = alicloud_kms_key.default.id
      force_delete_without_recovery = true
    }
    resource "alicloud_apig_secret" "default" {
      gateway_type  = "API"
      name          = var.name
      secret_source = "KMS"
      secret_data   = alicloud_kms_secret.default.secret_data
      kms_config = {
        kms_instance_id = alicloud_kms_secret.default.dkms_instance_id
        kms_key_id      = alicloud_kms_secret.default.encryption_key_id
      }
    }
    variable "name" {
      type    = string
      default = "terraform-example"
    }
    

    Create Secret Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new Secret(name: string, args: SecretArgs, opts?: CustomResourceOptions);
    @overload
    def Secret(resource_name: str,
               args: SecretArgs,
               opts: Optional[ResourceOptions] = None)
    
    @overload
    def Secret(resource_name: str,
               opts: Optional[ResourceOptions] = None,
               gateway_type: Optional[str] = None,
               kms_config: Optional[SecretKmsConfigArgs] = None,
               secret_data: Optional[str] = None,
               secret_source: Optional[str] = None,
               description: Optional[str] = None,
               name: Optional[str] = None)
    func NewSecret(ctx *Context, name string, args SecretArgs, opts ...ResourceOption) (*Secret, error)
    public Secret(string name, SecretArgs args, CustomResourceOptions? opts = null)
    public Secret(String name, SecretArgs args)
    public Secret(String name, SecretArgs args, CustomResourceOptions options)
    
    type: alicloud:apig:Secret
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "alicloud_apig_secret" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args SecretArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args SecretArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args SecretArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args SecretArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args SecretArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var secretResource = new AliCloud.Apig.Secret("secretResource", new()
    {
        GatewayType = "string",
        KmsConfig = new AliCloud.Apig.Inputs.SecretKmsConfigArgs
        {
            KmsInstanceId = "string",
            KmsKeyId = "string",
        },
        SecretData = "string",
        SecretSource = "string",
        Description = "string",
        Name = "string",
    });
    
    example, err := apig.NewSecret(ctx, "secretResource", &apig.SecretArgs{
    	GatewayType: pulumi.String("string"),
    	KmsConfig: &apig.SecretKmsConfigArgs{
    		KmsInstanceId: pulumi.String("string"),
    		KmsKeyId:      pulumi.String("string"),
    	},
    	SecretData:   pulumi.String("string"),
    	SecretSource: pulumi.String("string"),
    	Description:  pulumi.String("string"),
    	Name:         pulumi.String("string"),
    })
    
    resource "alicloud_apig_secret" "secretResource" {
      lifecycle {
        create_before_destroy = true
      }
      gateway_type = "string"
      kms_config = {
        kms_instance_id = "string"
        kms_key_id      = "string"
      }
      secret_data   = "string"
      secret_source = "string"
      description   = "string"
      name          = "string"
    }
    
    var secretResource = new com.pulumi.alicloud.apig.Secret("secretResource", com.pulumi.alicloud.apig.SecretArgs.builder()
        .gatewayType("string")
        .kmsConfig(SecretKmsConfigArgs.builder()
            .kmsInstanceId("string")
            .kmsKeyId("string")
            .build())
        .secretData("string")
        .secretSource("string")
        .description("string")
        .name("string")
        .build());
    
    secret_resource = alicloud.apig.Secret("secretResource",
        gateway_type="string",
        kms_config={
            "kms_instance_id": "string",
            "kms_key_id": "string",
        },
        secret_data="string",
        secret_source="string",
        description="string",
        name="string")
    
    const secretResource = new alicloud.apig.Secret("secretResource", {
        gatewayType: "string",
        kmsConfig: {
            kmsInstanceId: "string",
            kmsKeyId: "string",
        },
        secretData: "string",
        secretSource: "string",
        description: "string",
        name: "string",
    });
    
    type: alicloud:apig:Secret
    properties:
        description: string
        gatewayType: string
        kmsConfig:
            kmsInstanceId: string
            kmsKeyId: string
        name: string
        secretData: string
        secretSource: string
    

    Secret Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The Secret resource accepts the following input properties:

    GatewayType string
    The gateway type.
    KmsConfig Pulumi.AliCloud.Apig.Inputs.SecretKmsConfig
    The KMS config of the secret. See kmsConfig below.
    SecretData string
    The KMS credential value.
    SecretSource string
    The source of the key.
    Description string
    The secret description.
    Name string
    The secret name.
    GatewayType string
    The gateway type.
    KmsConfig SecretKmsConfigArgs
    The KMS config of the secret. See kmsConfig below.
    SecretData string
    The KMS credential value.
    SecretSource string
    The source of the key.
    Description string
    The secret description.
    Name string
    The secret name.
    gateway_type string
    The gateway type.
    kms_config object
    The KMS config of the secret. See kmsConfig below.
    secret_data string
    The KMS credential value.
    secret_source string
    The source of the key.
    description string
    The secret description.
    name string
    The secret name.
    gatewayType String
    The gateway type.
    kmsConfig SecretKmsConfig
    The KMS config of the secret. See kmsConfig below.
    secretData String
    The KMS credential value.
    secretSource String
    The source of the key.
    description String
    The secret description.
    name String
    The secret name.
    gatewayType string
    The gateway type.
    kmsConfig SecretKmsConfig
    The KMS config of the secret. See kmsConfig below.
    secretData string
    The KMS credential value.
    secretSource string
    The source of the key.
    description string
    The secret description.
    name string
    The secret name.
    gateway_type str
    The gateway type.
    kms_config SecretKmsConfigArgs
    The KMS config of the secret. See kmsConfig below.
    secret_data str
    The KMS credential value.
    secret_source str
    The source of the key.
    description str
    The secret description.
    name str
    The secret name.
    gatewayType String
    The gateway type.
    kmsConfig Property Map
    The KMS config of the secret. See kmsConfig below.
    secretData String
    The KMS credential value.
    secretSource String
    The source of the key.
    description String
    The secret description.
    name String
    The secret name.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the Secret resource produces the following output properties:

    CreateTimestamp int
    The creation timestamp of the secret.
    Id string
    The provider-assigned unique ID for this managed resource.
    ReferenceCount int
    The reference count of the secret.
    Status string
    The status of the secret.
    UpdateTimestamp int
    The update timestamp of the secret.
    CreateTimestamp int
    The creation timestamp of the secret.
    Id string
    The provider-assigned unique ID for this managed resource.
    ReferenceCount int
    The reference count of the secret.
    Status string
    The status of the secret.
    UpdateTimestamp int
    The update timestamp of the secret.
    create_timestamp number
    The creation timestamp of the secret.
    id string
    The provider-assigned unique ID for this managed resource.
    reference_count number
    The reference count of the secret.
    status string
    The status of the secret.
    update_timestamp number
    The update timestamp of the secret.
    createTimestamp Integer
    The creation timestamp of the secret.
    id String
    The provider-assigned unique ID for this managed resource.
    referenceCount Integer
    The reference count of the secret.
    status String
    The status of the secret.
    updateTimestamp Integer
    The update timestamp of the secret.
    createTimestamp number
    The creation timestamp of the secret.
    id string
    The provider-assigned unique ID for this managed resource.
    referenceCount number
    The reference count of the secret.
    status string
    The status of the secret.
    updateTimestamp number
    The update timestamp of the secret.
    create_timestamp int
    The creation timestamp of the secret.
    id str
    The provider-assigned unique ID for this managed resource.
    reference_count int
    The reference count of the secret.
    status str
    The status of the secret.
    update_timestamp int
    The update timestamp of the secret.
    createTimestamp Number
    The creation timestamp of the secret.
    id String
    The provider-assigned unique ID for this managed resource.
    referenceCount Number
    The reference count of the secret.
    status String
    The status of the secret.
    updateTimestamp Number
    The update timestamp of the secret.

    Look up Existing Secret Resource

    Get an existing Secret resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: SecretState, opts?: CustomResourceOptions): Secret
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            create_timestamp: Optional[int] = None,
            description: Optional[str] = None,
            gateway_type: Optional[str] = None,
            kms_config: Optional[SecretKmsConfigArgs] = None,
            name: Optional[str] = None,
            reference_count: Optional[int] = None,
            secret_data: Optional[str] = None,
            secret_source: Optional[str] = None,
            status: Optional[str] = None,
            update_timestamp: Optional[int] = None) -> Secret
    func GetSecret(ctx *Context, name string, id IDInput, state *SecretState, opts ...ResourceOption) (*Secret, error)
    public static Secret Get(string name, Input<string> id, SecretState? state, CustomResourceOptions? opts = null)
    public static Secret get(String name, Output<String> id, SecretState state, CustomResourceOptions options)
    resources:  _:    type: alicloud:apig:Secret    get:      id: ${id}
    import {
      to = alicloud_apig_secret.example
      id = "${id}"
    }
    
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    CreateTimestamp int
    The creation timestamp of the secret.
    Description string
    The secret description.
    GatewayType string
    The gateway type.
    KmsConfig Pulumi.AliCloud.Apig.Inputs.SecretKmsConfig
    The KMS config of the secret. See kmsConfig below.
    Name string
    The secret name.
    ReferenceCount int
    The reference count of the secret.
    SecretData string
    The KMS credential value.
    SecretSource string
    The source of the key.
    Status string
    The status of the secret.
    UpdateTimestamp int
    The update timestamp of the secret.
    CreateTimestamp int
    The creation timestamp of the secret.
    Description string
    The secret description.
    GatewayType string
    The gateway type.
    KmsConfig SecretKmsConfigArgs
    The KMS config of the secret. See kmsConfig below.
    Name string
    The secret name.
    ReferenceCount int
    The reference count of the secret.
    SecretData string
    The KMS credential value.
    SecretSource string
    The source of the key.
    Status string
    The status of the secret.
    UpdateTimestamp int
    The update timestamp of the secret.
    create_timestamp number
    The creation timestamp of the secret.
    description string
    The secret description.
    gateway_type string
    The gateway type.
    kms_config object
    The KMS config of the secret. See kmsConfig below.
    name string
    The secret name.
    reference_count number
    The reference count of the secret.
    secret_data string
    The KMS credential value.
    secret_source string
    The source of the key.
    status string
    The status of the secret.
    update_timestamp number
    The update timestamp of the secret.
    createTimestamp Integer
    The creation timestamp of the secret.
    description String
    The secret description.
    gatewayType String
    The gateway type.
    kmsConfig SecretKmsConfig
    The KMS config of the secret. See kmsConfig below.
    name String
    The secret name.
    referenceCount Integer
    The reference count of the secret.
    secretData String
    The KMS credential value.
    secretSource String
    The source of the key.
    status String
    The status of the secret.
    updateTimestamp Integer
    The update timestamp of the secret.
    createTimestamp number
    The creation timestamp of the secret.
    description string
    The secret description.
    gatewayType string
    The gateway type.
    kmsConfig SecretKmsConfig
    The KMS config of the secret. See kmsConfig below.
    name string
    The secret name.
    referenceCount number
    The reference count of the secret.
    secretData string
    The KMS credential value.
    secretSource string
    The source of the key.
    status string
    The status of the secret.
    updateTimestamp number
    The update timestamp of the secret.
    create_timestamp int
    The creation timestamp of the secret.
    description str
    The secret description.
    gateway_type str
    The gateway type.
    kms_config SecretKmsConfigArgs
    The KMS config of the secret. See kmsConfig below.
    name str
    The secret name.
    reference_count int
    The reference count of the secret.
    secret_data str
    The KMS credential value.
    secret_source str
    The source of the key.
    status str
    The status of the secret.
    update_timestamp int
    The update timestamp of the secret.
    createTimestamp Number
    The creation timestamp of the secret.
    description String
    The secret description.
    gatewayType String
    The gateway type.
    kmsConfig Property Map
    The KMS config of the secret. See kmsConfig below.
    name String
    The secret name.
    referenceCount Number
    The reference count of the secret.
    secretData String
    The KMS credential value.
    secretSource String
    The source of the key.
    status String
    The status of the secret.
    updateTimestamp Number
    The update timestamp of the secret.

    Supporting Types

    SecretKmsConfig, SecretKmsConfigArgs

    KmsInstanceId string
    The KMS instance ID.
    KmsKeyId string
    The KMS key ID.
    KmsInstanceId string
    The KMS instance ID.
    KmsKeyId string
    The KMS key ID.
    kms_instance_id string
    The KMS instance ID.
    kms_key_id string
    The KMS key ID.
    kmsInstanceId String
    The KMS instance ID.
    kmsKeyId String
    The KMS key ID.
    kmsInstanceId string
    The KMS instance ID.
    kmsKeyId string
    The KMS key ID.
    kms_instance_id str
    The KMS instance ID.
    kms_key_id str
    The KMS key ID.
    kmsInstanceId String
    The KMS instance ID.
    kmsKeyId String
    The KMS key ID.

    Import

    APIG Secret can be imported using the id, e.g.

    $ pulumi import alicloud:apig/secret:Secret example <secret_id>
    

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    Alibaba Cloud pulumi/pulumi-alicloud
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the alicloud Terraform Provider.
    alicloud logo alicloud logo
    Viewing docs for Alibaba Cloud v3.108.0
    published on Thursday, Sep 17, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial