1. Registry
  2. Packages
  3. AWS
  4. API Docs
  5. secretsmanager
  6. SecretRotation
Viewing docs for AWS v7.48.0
published on Tuesday, Sep 22, 2026 by Pulumi
aws logo aws logo
Viewing docs for AWS v7.48.0
published on Tuesday, Sep 22, 2026 by Pulumi

    Provides a resource to manage AWS Secrets Manager secret rotation. To manage a secret, see the aws.secretsmanager.Secret resource. To manage a secret value, see the aws.secretsmanager.SecretVersion resource.

    Example Usage

    Basic

    import * as pulumi from "@pulumi/pulumi";
    import * as aws from "@pulumi/aws";
    
    const example = new aws.secretsmanager.SecretRotation("example", {
        rotationRules: {
            automaticallyAfterDays: 30,
        },
        secretId: exampleAwsSecretsmanagerSecret.id,
        rotationLambdaArn: exampleAwsLambdaFunction.arn,
    });
    
    import pulumi
    import pulumi_aws as aws
    
    example = aws.secretsmanager.SecretRotation("example",
        rotation_rules={
            "automatically_after_days": 30,
        },
        secret_id=example_aws_secretsmanager_secret["id"],
        rotation_lambda_arn=example_aws_lambda_function["arn"])
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/secretsmanager"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := secretsmanager.NewSecretRotation(ctx, "example", &secretsmanager.SecretRotationArgs{
    			RotationRules: &secretsmanager.SecretRotationRotationRulesArgs{
    				AutomaticallyAfterDays: pulumi.Int(30),
    			},
    			SecretId:          pulumi.Any(exampleAwsSecretsmanagerSecret.Id),
    			RotationLambdaArn: pulumi.Any(exampleAwsLambdaFunction.Arn),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Aws = Pulumi.Aws;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Aws.SecretsManager.SecretRotation("example", new()
        {
            RotationRules = new Aws.SecretsManager.Inputs.SecretRotationRotationRulesArgs
            {
                AutomaticallyAfterDays = 30,
            },
            SecretId = exampleAwsSecretsmanagerSecret.Id,
            RotationLambdaArn = exampleAwsLambdaFunction.Arn,
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.aws.secretsmanager.SecretRotation;
    import com.pulumi.aws.secretsmanager.SecretRotationArgs;
    import com.pulumi.aws.secretsmanager.inputs.SecretRotationRotationRulesArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new SecretRotation("example", SecretRotationArgs.builder()
                .rotationRules(SecretRotationRotationRulesArgs.builder()
                    .automaticallyAfterDays(30)
                    .build())
                .secretId(exampleAwsSecretsmanagerSecret.id())
                .rotationLambdaArn(exampleAwsLambdaFunction.arn())
                .build());
    
        }
    }
    
    resources:
      example:
        type: aws:secretsmanager:SecretRotation
        properties:
          rotationRules:
            automaticallyAfterDays: 30
          secretId: ${exampleAwsSecretsmanagerSecret.id}
          rotationLambdaArn: ${exampleAwsLambdaFunction.arn}
    
    pulumi {
      required_providers {
        aws = {
          source = "pulumi/aws"
        }
      }
    }
    
    resource "aws_secretsmanager_secretrotation" "example" {
      rotation_rules = {
        automatically_after_days = 30
      }
      secret_id           = exampleAwsSecretsmanagerSecret.id
      rotation_lambda_arn = exampleAwsLambdaFunction.arn
    }
    

    Managed External Secret Rotation

    For managed external secrets that are rotated by AWS partner integrations:

    import * as pulumi from "@pulumi/pulumi";
    import * as aws from "@pulumi/aws";
    
    const example = new aws.secretsmanager.Secret("example", {
        name: "example-salesforce-client-secret",
        type: "SalesforceClientSecret",
    });
    const exampleSecretRotation = new aws.secretsmanager.SecretRotation("example", {
        rotationRules: {
            automaticallyAfterDays: Number(rotationDays),
        },
        externalSecretRotationMetadatas: [
            {
                key: "adminSecretArn",
                value: example.arn,
            },
            {
                key: "apiVersion",
                value: "v65.0",
            },
        ],
        secretId: example.id,
        externalSecretRotationRoleArn: exampleAwsIamRole.arn,
    });
    
    import pulumi
    import pulumi_aws as aws
    
    example = aws.secretsmanager.Secret("example",
        name="example-salesforce-client-secret",
        type="SalesforceClientSecret")
    example_secret_rotation = aws.secretsmanager.SecretRotation("example",
        rotation_rules={
            "automatically_after_days": int(rotation_days),
        },
        external_secret_rotation_metadatas=[
            {
                "key": "adminSecretArn",
                "value": example.arn,
            },
            {
                "key": "apiVersion",
                "value": "v65.0",
            },
        ],
        secret_id=example.id,
        external_secret_rotation_role_arn=example_aws_iam_role["arn"])
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/secretsmanager"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		example, err := secretsmanager.NewSecret(ctx, "example", &secretsmanager.SecretArgs{
    			Name: pulumi.String("example-salesforce-client-secret"),
    			Type: pulumi.String("SalesforceClientSecret"),
    		})
    		if err != nil {
    			return err
    		}
    		_, err = secretsmanager.NewSecretRotation(ctx, "example", &secretsmanager.SecretRotationArgs{
    			RotationRules: &secretsmanager.SecretRotationRotationRulesArgs{
    				AutomaticallyAfterDays: pulumi.Any(rotationDays),
    			},
    			ExternalSecretRotationMetadatas: secretsmanager.SecretRotationExternalSecretRotationMetadataArray{
    				&secretsmanager.SecretRotationExternalSecretRotationMetadataArgs{
    					Key:   pulumi.String("adminSecretArn"),
    					Value: example.Arn,
    				},
    				&secretsmanager.SecretRotationExternalSecretRotationMetadataArgs{
    					Key:   pulumi.String("apiVersion"),
    					Value: pulumi.String("v65.0"),
    				},
    			},
    			SecretId:                      example.ID().ToIDOutput().ToStringOutput(),
    			ExternalSecretRotationRoleArn: pulumi.Any(exampleAwsIamRole.Arn),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Aws = Pulumi.Aws;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Aws.SecretsManager.Secret("example", new()
        {
            Name = "example-salesforce-client-secret",
            Type = "SalesforceClientSecret",
        });
    
        var exampleSecretRotation = new Aws.SecretsManager.SecretRotation("example", new()
        {
            RotationRules = new Aws.SecretsManager.Inputs.SecretRotationRotationRulesArgs
            {
                AutomaticallyAfterDays = rotationDays,
            },
            ExternalSecretRotationMetadatas = new[]
            {
                new Aws.SecretsManager.Inputs.SecretRotationExternalSecretRotationMetadataArgs
                {
                    Key = "adminSecretArn",
                    Value = example.Arn,
                },
                new Aws.SecretsManager.Inputs.SecretRotationExternalSecretRotationMetadataArgs
                {
                    Key = "apiVersion",
                    Value = "v65.0",
                },
            },
            SecretId = example.Id,
            ExternalSecretRotationRoleArn = exampleAwsIamRole.Arn,
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.aws.secretsmanager.Secret;
    import com.pulumi.aws.secretsmanager.SecretArgs;
    import com.pulumi.aws.secretsmanager.SecretRotation;
    import com.pulumi.aws.secretsmanager.SecretRotationArgs;
    import com.pulumi.aws.secretsmanager.inputs.SecretRotationRotationRulesArgs;
    import com.pulumi.aws.secretsmanager.inputs.SecretRotationExternalSecretRotationMetadataArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new Secret("example", SecretArgs.builder()
                .name("example-salesforce-client-secret")
                .type("SalesforceClientSecret")
                .build());
    
            var exampleSecretRotation = new SecretRotation("exampleSecretRotation", SecretRotationArgs.builder()
                .rotationRules(SecretRotationRotationRulesArgs.builder()
                    .automaticallyAfterDays(rotationDays)
                    .build())
                .externalSecretRotationMetadatas(            
                    SecretRotationExternalSecretRotationMetadataArgs.builder()
                        .key("adminSecretArn")
                        .value(example.arn())
                        .build(),
                    SecretRotationExternalSecretRotationMetadataArgs.builder()
                        .key("apiVersion")
                        .value("v65.0")
                        .build())
                .secretId(example.id())
                .externalSecretRotationRoleArn(exampleAwsIamRole.arn())
                .build());
    
        }
    }
    
    resources:
      example:
        type: aws:secretsmanager:Secret
        properties:
          name: example-salesforce-client-secret
          type: SalesforceClientSecret
      exampleSecretRotation:
        type: aws:secretsmanager:SecretRotation
        name: example
        properties:
          rotationRules:
            automaticallyAfterDays: ${rotationDays}
          externalSecretRotationMetadatas:
            - key: adminSecretArn
              value: ${example.arn}
            - key: apiVersion
              value: v65.0
          secretId: ${example.id}
          externalSecretRotationRoleArn: ${exampleAwsIamRole.arn}
    
    pulumi {
      required_providers {
        aws = {
          source = "pulumi/aws"
        }
      }
    }
    
    resource "aws_secretsmanager_secret" "example" {
      name = "example-salesforce-client-secret"
      type = "SalesforceClientSecret"
    }
    resource "aws_secretsmanager_secretrotation" "example" {
      rotation_rules = {
        automatically_after_days = rotationDays
      }
      external_secret_rotation_metadatas {
        key   = "adminSecretArn"
        value = aws_secretsmanager_secret.example.arn
      }
      external_secret_rotation_metadatas {
        key   = "apiVersion"
        value = "v65.0"
      }
      secret_id                         = aws_secretsmanager_secret.example.id
      external_secret_rotation_role_arn = exampleAwsIamRole.arn
    }
    

    For more information about managed external secrets and partner-specific metadata requirements, see the AWS documentation and partner-specific guides.

    Disable Rotation for a Managed Secret

    When a secret is managed by AWS, such as an RDS master user password secret created via manageMasterUserPassword, rotation is enabled automatically. Set rotationEnabled to false (and omit rotationRules) to turn that rotation off:

    import * as pulumi from "@pulumi/pulumi";
    import * as aws from "@pulumi/aws";
    
    const example = new aws.rds.Instance("example", {manageMasterUserPassword: true});
    const exampleSecretRotation = new aws.secretsmanager.SecretRotation("example", {
        secretId: example.masterUserSecrets[0].secretArn,
        rotationEnabled: false,
    });
    
    import pulumi
    import pulumi_aws as aws
    
    example = aws.rds.Instance("example", manage_master_user_password=True)
    example_secret_rotation = aws.secretsmanager.SecretRotation("example",
        secret_id=example.master_user_secrets[0].secret_arn,
        rotation_enabled=False)
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/rds"
    	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/secretsmanager"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		example, err := rds.NewInstance(ctx, "example", &rds.InstanceArgs{
    			ManageMasterUserPassword: pulumi.Bool(true),
    		})
    		if err != nil {
    			return err
    		}
    		_, err = secretsmanager.NewSecretRotation(ctx, "example", &secretsmanager.SecretRotationArgs{
    			SecretId: example.MasterUserSecrets.ApplyT(func(masterUserSecrets []rds.InstanceMasterUserSecret) (*string, error) {
    				return masterUserSecrets[0].SecretArn, nil
    			}).(pulumi.StringPtrOutput),
    			RotationEnabled: pulumi.Bool(false),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Aws = Pulumi.Aws;
    
    return await Deployment.RunAsync(() => 
    {
        var example = new Aws.Rds.Instance("example", new()
        {
            ManageMasterUserPassword = true,
        });
    
        var exampleSecretRotation = new Aws.SecretsManager.SecretRotation("example", new()
        {
            SecretId = example.MasterUserSecrets.Apply(masterUserSecrets => masterUserSecrets[0].SecretArn),
            RotationEnabled = false,
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.aws.rds.Instance;
    import com.pulumi.aws.rds.InstanceArgs;
    import com.pulumi.aws.secretsmanager.SecretRotation;
    import com.pulumi.aws.secretsmanager.SecretRotationArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var example = new Instance("example", InstanceArgs.builder()
                .manageMasterUserPassword(true)
                .build());
    
            var exampleSecretRotation = new SecretRotation("exampleSecretRotation", SecretRotationArgs.builder()
                .secretId(example.masterUserSecrets().applyValue(_masterUserSecrets -> _masterUserSecrets[0].secretArn()))
                .rotationEnabled(false)
                .build());
    
        }
    }
    
    resources:
      example:
        type: aws:rds:Instance
        properties:
          manageMasterUserPassword: true
      exampleSecretRotation:
        type: aws:secretsmanager:SecretRotation
        name: example
        properties:
          secretId: ${example.masterUserSecrets[0].secretArn}
          rotationEnabled: false
    
    pulumi {
      required_providers {
        aws = {
          source = "pulumi/aws"
        }
      }
    }
    
    resource "aws_rds_instance" "example" {
      manage_master_user_password = true
    }
    resource "aws_secretsmanager_secretrotation" "example" {
      secret_id        = aws_rds_instance.example.master_user_secrets[0].secret_arn
      rotation_enabled = false
    }
    

    NOTE: For Amazon Aurora and other clustered engines, rotation is finalized once a cluster instance is available, and AWS re-enables rotation if it is cancelled before then. Ensure this resource depends on the cluster instance (for example, with dependsOn = [aws_rds_cluster_instance.example]) so the cancellation is applied after the instance is available.

    When rotationEnabled is false, rotationRules must be omitted. If you toggle rotation on and off through a variable (for example, in a module), gate the block with a dynamic block so it is only present when rotation is enabled:

    import * as pulumi from "@pulumi/pulumi";
    import * as aws from "@pulumi/aws";
    
    function singleOrNone<T>(elements: pulumi.Input<T>[]): pulumi.Input<T> | undefined {
        if (elements.length > 1) {
            throw new Error("singleOrNone expected input list to have a single element");
        }
        return elements[0];
    }
    
    const config = new pulumi.Config();
    const rotationEnabled = config.getBoolean("rotationEnabled") || true;
    const example = new aws.secretsmanager.SecretRotation("example", {
        rotationRules: singleOrNone(rotationEnabled ? [{
            automaticallyAfterDays: 30,
        }] : []),
        secretId: exampleAwsDbInstance.masterUserSecret[0].secretArn,
        rotationEnabled: rotationEnabled,
    });
    
    import pulumi
    import pulumi_aws as aws
    
    def single_or_none(elements):
        if len(elements) > 1:
            raise Exception("single_or_none expected input list to have a single element")
        return elements[0] if elements else None
    
    
    config = pulumi.Config()
    rotation_enabled = config.get_bool("rotationEnabled")
    if rotation_enabled is None:
        rotation_enabled = True
    example = aws.secretsmanager.SecretRotation("example",
        rotation_rules=single_or_none([{
            "automaticallyAfterDays": 30,
        }] if rotation_enabled else []),
        secret_id=example_aws_db_instance["masterUserSecret"][0]["secretArn"],
        rotation_enabled=rotation_enabled)
    
    package main
    
    import (
    	"fmt"
    
    	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/secretsmanager"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi/config"
    )
    
    func singleOrNone[T any](elements []T) T {
    	if len(elements) != 1 {
    		panic(fmt.Errorf("singleOrNone expected input slice to have a single element"))
    	}
    	return elements[0]
    }
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		cfg := config.New(ctx, "")
    		rotationEnabled := true
    		if param := cfg.GetBool("rotationEnabled"); param {
    			rotationEnabled = param
    		}
    		var tmp0 []map[string]int
    		if rotationEnabled {
    			tmp0 = []map[string]int{
    				{
    					"automaticallyAfterDays": 30,
    				},
    			}
    		} else {
    			tmp0 = []interface{}{}
    		}
    		_, err := secretsmanager.NewSecretRotation(ctx, "example", &secretsmanager.SecretRotationArgs{
    			RotationRules:   singleOrNone(tmp0),
    			SecretId:        pulumi.Any(exampleAwsDbInstance.MasterUserSecret[0].SecretArn),
    			RotationEnabled: pulumi.Bool(rotationEnabled),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Aws = Pulumi.Aws;
    
    return await Deployment.RunAsync(() => 
    {
        var config = new Config();
        var rotationEnabled = config.GetBoolean("rotationEnabled") ?? true;
        var example = new Aws.SecretsManager.SecretRotation("example", new()
        {
            RotationRules = Enumerable.SingleOrDefault(rotationEnabled ? new[]
            {
                
                {
                    { "automaticallyAfterDays", 30 },
                },
            } : new[] {}),
            SecretId = exampleAwsDbInstance.MasterUserSecret[0].SecretArn,
            RotationEnabled = rotationEnabled,
        });
    
    });
    
    Example coming soon!
    
    Example coming soon!
    
    pulumi {
      required_providers {
        aws = {
          source = "pulumi/aws"
        }
      }
    }
    
    resource "aws_secretsmanager_secretrotation" "example" {
      rotation_rules = one(var.rotationEnabled ? [{
        "automaticallyAfterDays" = 30
      }] : [])
      secret_id        = exampleAwsDbInstance.masterUserSecret[0].secretArn
      rotation_enabled = var.rotationEnabled
    }
    variable "rotationEnabled" {
      type    = bool
      default = true
    }
    

    Rotation Configuration

    To enable automatic secret rotation, the Secrets Manager service requires usage of a Lambda function. The Rotate Secrets section in the Secrets Manager User Guide provides additional information about deploying a prebuilt Lambda functions for supported credential rotation (e.g., RDS) or deploying a custom Lambda function.

    NOTE: Configuring rotation causes the secret to rotate once as soon as you enable rotation. Before you do this, you must ensure that all of your applications that use the credentials stored in the secret are updated to retrieve the secret from AWS Secrets Manager. The old credentials might no longer be usable after the initial rotation and any applications that you fail to update will break as soon as the old credentials are no longer valid.

    NOTE: If you cancel a rotation that is in progress (by removing the rotation configuration), it can leave the VersionStage labels in an unexpected state. Depending on what step of the rotation was in progress, you might need to remove the staging label AWSPENDING from the partially created version, specified by the SecretVersionId response value. You should also evaluate the partially rotated new version to see if it should be deleted, which you can do by removing all staging labels from the new version’s VersionStage field.

    Create SecretRotation Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new SecretRotation(name: string, args: SecretRotationArgs, opts?: CustomResourceOptions);
    @overload
    def SecretRotation(resource_name: str,
                       args: SecretRotationArgs,
                       opts: Optional[ResourceOptions] = None)
    
    @overload
    def SecretRotation(resource_name: str,
                       opts: Optional[ResourceOptions] = None,
                       secret_id: Optional[str] = None,
                       external_secret_rotation_metadatas: Optional[Sequence[SecretRotationExternalSecretRotationMetadataArgs]] = None,
                       external_secret_rotation_role_arn: Optional[str] = None,
                       region: Optional[str] = None,
                       rotate_immediately: Optional[bool] = None,
                       rotation_enabled: Optional[bool] = None,
                       rotation_lambda_arn: Optional[str] = None,
                       rotation_rules: Optional[SecretRotationRotationRulesArgs] = None)
    func NewSecretRotation(ctx *Context, name string, args SecretRotationArgs, opts ...ResourceOption) (*SecretRotation, error)
    public SecretRotation(string name, SecretRotationArgs args, CustomResourceOptions? opts = null)
    public SecretRotation(String name, SecretRotationArgs args)
    public SecretRotation(String name, SecretRotationArgs args, CustomResourceOptions options)
    
    type: aws:secretsmanager:SecretRotation
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "aws_secretsmanager_secret_rotation" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args SecretRotationArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args SecretRotationArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args SecretRotationArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args SecretRotationArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args SecretRotationArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var secretRotationResource = new Aws.SecretsManager.SecretRotation("secretRotationResource", new()
    {
        SecretId = "string",
        ExternalSecretRotationMetadatas = new[]
        {
            new Aws.SecretsManager.Inputs.SecretRotationExternalSecretRotationMetadataArgs
            {
                Key = "string",
                Value = "string",
            },
        },
        ExternalSecretRotationRoleArn = "string",
        Region = "string",
        RotateImmediately = false,
        RotationEnabled = false,
        RotationLambdaArn = "string",
        RotationRules = new Aws.SecretsManager.Inputs.SecretRotationRotationRulesArgs
        {
            AutomaticallyAfterDays = 0,
            Duration = "string",
            ScheduleExpression = "string",
        },
    });
    
    example, err := secretsmanager.NewSecretRotation(ctx, "secretRotationResource", &secretsmanager.SecretRotationArgs{
    	SecretId: pulumi.String("string"),
    	ExternalSecretRotationMetadatas: secretsmanager.SecretRotationExternalSecretRotationMetadataArray{
    		&secretsmanager.SecretRotationExternalSecretRotationMetadataArgs{
    			Key:   pulumi.String("string"),
    			Value: pulumi.String("string"),
    		},
    	},
    	ExternalSecretRotationRoleArn: pulumi.String("string"),
    	Region:                        pulumi.String("string"),
    	RotateImmediately:             pulumi.Bool(false),
    	RotationEnabled:               pulumi.Bool(false),
    	RotationLambdaArn:             pulumi.String("string"),
    	RotationRules: &secretsmanager.SecretRotationRotationRulesArgs{
    		AutomaticallyAfterDays: pulumi.Int(0),
    		Duration:               pulumi.String("string"),
    		ScheduleExpression:     pulumi.String("string"),
    	},
    })
    
    resource "aws_secretsmanager_secret_rotation" "secretRotationResource" {
      lifecycle {
        create_before_destroy = true
      }
      secret_id = "string"
      external_secret_rotation_metadatas {
        key   = "string"
        value = "string"
      }
      external_secret_rotation_role_arn = "string"
      region                            = "string"
      rotate_immediately                = false
      rotation_enabled                  = false
      rotation_lambda_arn               = "string"
      rotation_rules = {
        automatically_after_days = 0
        duration                 = "string"
        schedule_expression      = "string"
      }
    }
    
    var secretRotationResource = new SecretRotation("secretRotationResource", SecretRotationArgs.builder()
        .secretId("string")
        .externalSecretRotationMetadatas(SecretRotationExternalSecretRotationMetadataArgs.builder()
            .key("string")
            .value("string")
            .build())
        .externalSecretRotationRoleArn("string")
        .region("string")
        .rotateImmediately(false)
        .rotationEnabled(false)
        .rotationLambdaArn("string")
        .rotationRules(SecretRotationRotationRulesArgs.builder()
            .automaticallyAfterDays(0)
            .duration("string")
            .scheduleExpression("string")
            .build())
        .build());
    
    secret_rotation_resource = aws.secretsmanager.SecretRotation("secretRotationResource",
        secret_id="string",
        external_secret_rotation_metadatas=[{
            "key": "string",
            "value": "string",
        }],
        external_secret_rotation_role_arn="string",
        region="string",
        rotate_immediately=False,
        rotation_enabled=False,
        rotation_lambda_arn="string",
        rotation_rules={
            "automatically_after_days": 0,
            "duration": "string",
            "schedule_expression": "string",
        })
    
    const secretRotationResource = new aws.secretsmanager.SecretRotation("secretRotationResource", {
        secretId: "string",
        externalSecretRotationMetadatas: [{
            key: "string",
            value: "string",
        }],
        externalSecretRotationRoleArn: "string",
        region: "string",
        rotateImmediately: false,
        rotationEnabled: false,
        rotationLambdaArn: "string",
        rotationRules: {
            automaticallyAfterDays: 0,
            duration: "string",
            scheduleExpression: "string",
        },
    });
    
    type: aws:secretsmanager:SecretRotation
    properties:
        externalSecretRotationMetadatas:
            - key: string
              value: string
        externalSecretRotationRoleArn: string
        region: string
        rotateImmediately: false
        rotationEnabled: false
        rotationLambdaArn: string
        rotationRules:
            automaticallyAfterDays: 0
            duration: string
            scheduleExpression: string
        secretId: string
    

    SecretRotation Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The SecretRotation resource accepts the following input properties:

    SecretId string
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    ExternalSecretRotationMetadatas List<SecretRotationExternalSecretRotationMetadata>
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    ExternalSecretRotationRoleArn string
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    Region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    RotateImmediately bool
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    RotationEnabled bool
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    RotationLambdaArn string
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    RotationRules SecretRotationRotationRules
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    SecretId string
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    ExternalSecretRotationMetadatas []SecretRotationExternalSecretRotationMetadataArgs
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    ExternalSecretRotationRoleArn string
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    Region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    RotateImmediately bool
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    RotationEnabled bool
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    RotationLambdaArn string
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    RotationRules SecretRotationRotationRulesArgs
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secret_id string
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    external_secret_rotation_metadatas list(object)
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    external_secret_rotation_role_arn string
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotate_immediately bool
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotation_enabled bool
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotation_lambda_arn string
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotation_rules object
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secretId String
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    externalSecretRotationMetadatas List<SecretRotationExternalSecretRotationMetadata>
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    externalSecretRotationRoleArn String
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region String
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotateImmediately Boolean
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotationEnabled Boolean
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotationLambdaArn String
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotationRules SecretRotationRotationRules
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secretId string
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    externalSecretRotationMetadatas SecretRotationExternalSecretRotationMetadata[]
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    externalSecretRotationRoleArn string
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotateImmediately boolean
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotationEnabled boolean
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotationLambdaArn string
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotationRules SecretRotationRotationRules
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secret_id str
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    external_secret_rotation_metadatas Sequence[SecretRotationExternalSecretRotationMetadataArgs]
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    external_secret_rotation_role_arn str
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region str
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotate_immediately bool
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotation_enabled bool
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotation_lambda_arn str
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotation_rules SecretRotationRotationRulesArgs
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secretId String
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    externalSecretRotationMetadatas List<Property Map>
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    externalSecretRotationRoleArn String
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region String
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotateImmediately Boolean
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotationEnabled Boolean
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotationLambdaArn String
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotationRules Property Map
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the SecretRotation resource produces the following output properties:

    Id string
    The provider-assigned unique ID for this managed resource.
    Id string
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id str
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.

    Look up Existing SecretRotation Resource

    Get an existing SecretRotation resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: SecretRotationState, opts?: CustomResourceOptions): SecretRotation
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            external_secret_rotation_metadatas: Optional[Sequence[SecretRotationExternalSecretRotationMetadataArgs]] = None,
            external_secret_rotation_role_arn: Optional[str] = None,
            region: Optional[str] = None,
            rotate_immediately: Optional[bool] = None,
            rotation_enabled: Optional[bool] = None,
            rotation_lambda_arn: Optional[str] = None,
            rotation_rules: Optional[SecretRotationRotationRulesArgs] = None,
            secret_id: Optional[str] = None) -> SecretRotation
    func GetSecretRotation(ctx *Context, name string, id IDInput, state *SecretRotationState, opts ...ResourceOption) (*SecretRotation, error)
    public static SecretRotation Get(string name, Input<string> id, SecretRotationState? state, CustomResourceOptions? opts = null)
    public static SecretRotation get(String name, Output<String> id, SecretRotationState state, CustomResourceOptions options)
    resources:  _:    type: aws:secretsmanager:SecretRotation    get:      id: ${id}
    import {
      to = aws_secretsmanager_secret_rotation.example
      id = "${id}"
    }
    
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    ExternalSecretRotationMetadatas List<SecretRotationExternalSecretRotationMetadata>
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    ExternalSecretRotationRoleArn string
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    Region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    RotateImmediately bool
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    RotationEnabled bool
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    RotationLambdaArn string
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    RotationRules SecretRotationRotationRules
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    SecretId string
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    ExternalSecretRotationMetadatas []SecretRotationExternalSecretRotationMetadataArgs
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    ExternalSecretRotationRoleArn string
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    Region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    RotateImmediately bool
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    RotationEnabled bool
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    RotationLambdaArn string
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    RotationRules SecretRotationRotationRulesArgs
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    SecretId string
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    external_secret_rotation_metadatas list(object)
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    external_secret_rotation_role_arn string
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotate_immediately bool
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotation_enabled bool
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotation_lambda_arn string
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotation_rules object
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secret_id string
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    externalSecretRotationMetadatas List<SecretRotationExternalSecretRotationMetadata>
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    externalSecretRotationRoleArn String
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region String
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotateImmediately Boolean
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotationEnabled Boolean
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotationLambdaArn String
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotationRules SecretRotationRotationRules
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secretId String
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    externalSecretRotationMetadatas SecretRotationExternalSecretRotationMetadata[]
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    externalSecretRotationRoleArn string
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region string
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotateImmediately boolean
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotationEnabled boolean
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotationLambdaArn string
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotationRules SecretRotationRotationRules
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secretId string
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    external_secret_rotation_metadatas Sequence[SecretRotationExternalSecretRotationMetadataArgs]
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    external_secret_rotation_role_arn str
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region str
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotate_immediately bool
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotation_enabled bool
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotation_lambda_arn str
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotation_rules SecretRotationRotationRulesArgs
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secret_id str
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.
    externalSecretRotationMetadatas List<Property Map>
    Configuration block for metadata required by the external secret partner. Required for managed external secrets. See details below.
    externalSecretRotationRoleArn String
    ARN of the IAM role that allows Secrets Manager to rotate the secret held by a third-party partner. Required for managed external secrets.
    region String
    Region where this resource will be managed. Defaults to the Region set in the provider configuration.
    rotateImmediately Boolean
    Whether to rotate the secret immediately or wait until the next scheduled rotation window. The rotation schedule is defined in rotationRules. For secrets that use a Lambda rotation function to rotate, if you don't immediately rotate the secret, Secrets Manager tests the rotation configuration by running the testSecret step (https://docs.aws.amazon.com/secretsmanager/latest/userguide/rotate-secrets_how.html) of the Lambda rotation function. The test creates an AWSPENDING version of the secret and then removes it. Defaults to true.
    rotationEnabled Boolean
    Whether automatic rotation is enabled for the secret. Set to false to disable rotation on a secret whose rotation is otherwise managed by AWS (for example, an RDS master user password secret). When false, rotationRules must be omitted. Defaults to enabled when rotationRules is configured. Destroying this resource does not re-enable the automatic rotation that AWS configured.
    rotationLambdaArn String
    ARN of the Lambda function that can rotate the secret. Must be supplied if the secret is not managed by AWS.
    rotationRules Property Map
    Structure that defines the rotation configuration for this secret. Required unless rotationEnabled is false. Defined below.
    secretId String
    Secret to which you want to add a new version. You can specify either the ARN or the friendly name of the secret. The secret must already exist.

    Supporting Types

    SecretRotationExternalSecretRotationMetadata, SecretRotationExternalSecretRotationMetadataArgs

    Key string
    Metadata key name. Partner-specific keys are required for each external secret type. See partner documentation for required keys.
    Value string
    Metadata value for the specified key.
    Key string
    Metadata key name. Partner-specific keys are required for each external secret type. See partner documentation for required keys.
    Value string
    Metadata value for the specified key.
    key string
    Metadata key name. Partner-specific keys are required for each external secret type. See partner documentation for required keys.
    value string
    Metadata value for the specified key.
    key String
    Metadata key name. Partner-specific keys are required for each external secret type. See partner documentation for required keys.
    value String
    Metadata value for the specified key.
    key string
    Metadata key name. Partner-specific keys are required for each external secret type. See partner documentation for required keys.
    value string
    Metadata value for the specified key.
    key str
    Metadata key name. Partner-specific keys are required for each external secret type. See partner documentation for required keys.
    value str
    Metadata value for the specified key.
    key String
    Metadata key name. Partner-specific keys are required for each external secret type. See partner documentation for required keys.
    value String
    Metadata value for the specified key.

    SecretRotationRotationRules, SecretRotationRotationRulesArgs

    AutomaticallyAfterDays int
    Number of days between automatic scheduled rotations of the secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    Duration string
    The length of the rotation window in hours. For example, 3h for a three hour window.
    ScheduleExpression string
    cron() or rate() expression that defines the schedule for rotating your secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    AutomaticallyAfterDays int
    Number of days between automatic scheduled rotations of the secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    Duration string
    The length of the rotation window in hours. For example, 3h for a three hour window.
    ScheduleExpression string
    cron() or rate() expression that defines the schedule for rotating your secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    automatically_after_days number
    Number of days between automatic scheduled rotations of the secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    duration string
    The length of the rotation window in hours. For example, 3h for a three hour window.
    schedule_expression string
    cron() or rate() expression that defines the schedule for rotating your secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    automaticallyAfterDays Integer
    Number of days between automatic scheduled rotations of the secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    duration String
    The length of the rotation window in hours. For example, 3h for a three hour window.
    scheduleExpression String
    cron() or rate() expression that defines the schedule for rotating your secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    automaticallyAfterDays number
    Number of days between automatic scheduled rotations of the secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    duration string
    The length of the rotation window in hours. For example, 3h for a three hour window.
    scheduleExpression string
    cron() or rate() expression that defines the schedule for rotating your secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    automatically_after_days int
    Number of days between automatic scheduled rotations of the secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    duration str
    The length of the rotation window in hours. For example, 3h for a three hour window.
    schedule_expression str
    cron() or rate() expression that defines the schedule for rotating your secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    automaticallyAfterDays Number
    Number of days between automatic scheduled rotations of the secret. Either automaticallyAfterDays or scheduleExpression must be specified.
    duration String
    The length of the rotation window in hours. For example, 3h for a three hour window.
    scheduleExpression String
    cron() or rate() expression that defines the schedule for rotating your secret. Either automaticallyAfterDays or scheduleExpression must be specified.

    Import

    Identity Schema

    Required

    • secretId (String) ARN of the Secrets Manager secret.

    Using pulumi import, import aws.secretsmanager.SecretRotation using the secret ARN. For example:

    $ pulumi import aws:secretsmanager/secretRotation:SecretRotation example arn:aws:secretsmanager:us-east-1:123456789012:secret:example-123456
    

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    AWS Classic pulumi/pulumi-aws
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the aws Terraform Provider.
    aws logo aws logo
    Viewing docs for AWS v7.48.0
    published on Tuesday, Sep 22, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial