juju_secret_backend (Resource)

A resource that represents a Juju secret backend.

Secret backends store secret content. To learn more about secret backends, please visit: https://canonical.com/juju/docs/juju-cli/3.6/howto/manage-secret-backends/

Example Usage

resource "juju_secret_backend" "myvault" {
  name         = "myvault"
  backend_type = "vault"
  config_wo = {
    endpoint = "https://vault.example.com:8200"
    token    = "s.exampletoken"
  }
  config_wo_version     = 1
  token_rotate_interval = "24h"
}

Schema

Required

NOTE: Write-only arguments are supported in Terraform 1.11 and later.

  • backend_type (String) The type of the secret backend (e.g., ‘vault’, ‘kubernetes’).

  • config_wo (Map of String, Sensitive, Write-only ) The write-only backend configuration. Its content is never persisted to Terraform state, because it can contain sensitive data. Requires config_wo_version to be set; bump config_wo_version to apply changes to this value.

  • config_wo_version (Number) The version of config_wo. Increment this value to trigger an update of the write-only backend configuration.

  • name (String) The name of the secret backend.

Optional

  • token_rotate_interval (String) The interval at which the backend’s access credential/token should be rotated. Must be a duration string parsable by Go’s time.ParseDuration (e.g., ‘10m’, ‘1h’, ‘24h’).

Read-Only

  • id (String) The ID of this resource.

Import

Import is supported using the following syntax:

The terraform import command can be used, for example:

# Secret backends can be imported using their name.
$ terraform import juju_secret_backend.my_backend my-backend-name