/example-pulumi-secrets-policy

An example using Pulumi CrossGuard for policy as code to ensure a database password is secret and will be encrypted in the Pulumi stack state file.

Primary LanguageTypeScriptApache License 2.0Apache-2.0

example-pulumi-secrets-policy

An example using Pulumi CrossGuard for policy as code to ensure a database password is secret and will be encrypted in the Pulumi stack state file.

The example uses a few Pulumi features:

Usage (Local Policy Enforcement)

pulumi stack init
pulumi config set clusterPassword --secret
pulumi up --policy-pack policy-as-code

Usage (Server-Side Policy Enforcement)

pulumi stack init
pulumi config set clusterPassword --secret
cd policy-as-code
pulumi policy publish <org>
pulumi policy enable aws-typescript latest
cd ..
pulumi up