Google CloudLive-testedattested

Secret Manager Secrets

Secrets with versions, replication policy, rotation schedules, expiry and accessor IAM.

terraformGoogle Cloudgcp

Compare Secrets & Key Management across clouds →

Part of: GCP Production Landing Zone, GCP Kubernetes Platform

gcp-secret-managervizier v1.2.0

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-30 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o gcp-secret-manager-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/gcp-secret-manager/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle gcp-secret-manager-1.0.0.sigstore.json \
  gcp-secret-manager-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "70af2acc8868ab9e55250aea5989cb3dc04280c3defa06c91f8caf8b76ec1a7d  gcp-secret-manager-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "secret_manager" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-secret-manager/gcp"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/gcp-secret-manager/badge)](https://www.iac-bazaar.com/catalog/gcp-secret-manager?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, live-tested on IaC Bazaar: [Secret Manager Secrets](https://www.iac-bazaar.com/catalog/gcp-secret-manager?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "secret_manager" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-secret-manager/gcp"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: live-tested

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

gcp-secret-manager

A Secret Manager secret with a chosen replication policy (Google-managed automatic by default, or user-managed regions with optional CMEK for data-residency), an optional initial version that prefers the write-only path so the value never touches state, optional expiry and rotation notifications, and least-privilege accessor IAM. Works with Terraform and OpenTofu (>= 1.6), Google provider >= 7.0, < 8.0.

Secure defaults

  • No initial version by default — the value is set out of band (a controller / gcloud), so Terraform never owns plaintext.
  • Write-only seeding when you do seed — secret_data_wo (Terraform 1.11+) pushes a value that is never persisted to state; the state-stored secret_data path is available but discouraged, and the two are mutually exclusive (enforced as a precondition).
  • Least-privilege accessor IAM — accessor_members are granted exactly roles/secretmanager.secretAccessor (read-only) on this one secret, via additive google_secret_manager_secret_iam_member bindings.
  • CMEK-capable — user-managed replicas can be encrypted with your own KMS key (replica_kms_key_name); a precondition rejects CMEK with automatic replication, which uses Google-managed keys.
  • Recovery window — version_destroy_ttl keeps destroyed versions recoverable for a grace period.
  • Rotation is notification-only — Secret Manager pings a Pub/Sub topic on schedule (a precondition requires notification_topics when rotation is set); an external rotator mints the new value.

Requirements

  • Terraform or OpenTofu >= 1.6
  • hashicorp/google >= 7.0, < 8.0

License

Commercial — LicenseRef-IaCBazaar-Commercial.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs

Related modules

Static validatedLive test pending

gcp-certificate-authority

The DevOps tier does not persist the certificates it issues: no record, no CRL, no revocation - a year-long certificate from it can only answer a key compromise by the CA being distrusted whole. ENTERPRISE tier with the CRL published, a 90-day ceiling on every certificate, RSA below 2048 refused, and deletion protection on because deleting a CA invalidates everything it signed.

View module
Live-tested

gcp-certificate-manager

A Certificate Manager certificate map for external HTTPS load balancers, with an optional Google-managed certificate and DNS authorization provisioned when you supply a domain you control.

View module
Live-tested

gcp-kms

Keyrings and rotation-enabled crypto keys with per-key IAM for CMEK across GCS, BigQuery, Cloud SQL and disks.

View module
Static validatedLive test pending

huawei-csms-secret

A secret in Huawei Cloud Secrets Manager whose value is a sensitive variable supplied at apply time and never output, encrypted with a KMS key of yours rather than the account's default CSMS key (the default by name), with an expiry after which CSMS flags it (none by name) and event subscriptions that notice version changes and expiry.

View module
Static validatedLive test pending

exoscale-kms-key

A key is zonal unless multi-zone, which is the surprise at the first cross-zone restore; and the service has no automatic rotation setting and no flag that refuses deletion, so a key is deleted in one call. Multi-zone unless told otherwise, and outputs that say rotation and deletion protection are not available, so nothing downstream assumes a control that is not there.

View module
Static validatedLive test pending

alicloud-kms-key

automatic_rotation defaults to Disabled, so today's key material encrypts everything for the life of the account; a key scheduled for deletion is gone after its window with everything encrypted under it; and deletion_protection, the switch that refuses the schedule, defaults to off. Rotation on at your interval, deletion protection on and off by name, the maximum pending window, and an alias.

View module