lemon-machine-35564
03/12/2021, 3:51 PMType 'Output<string>' is not assignable to type 'string'.
every single day? 😄helpful-van-82564
03/12/2021, 5:04 PMadamant-translator-31969
03/12/2021, 5:21 PMerror: could not deserialize deployment: unexpected end of JSON input
when I run pulumi stack import --file <stack>.<number>.json
breezy-apartment-46543
03/12/2021, 7:29 PMworried-knife-31967
03/12/2021, 7:43 PMbreezy-apartment-46543
03/12/2021, 7:46 PMbreezy-apartment-46543
03/12/2021, 7:47 PMloud-battery-37784
03/12/2021, 7:52 PMbreezy-apartment-46543
03/12/2021, 7:54 PMworried-knife-31967
03/12/2021, 8:23 PMworried-knife-31967
03/12/2021, 8:24 PMclever-plumber-29709
03/12/2021, 8:40 PMpulumi.stack.yml
config:
proj:data:
services:
foo: bar
priv:
secure: AAABAB+T(...)sEmx8=
__main__.py
import pulumi
conf = pulumi_config.require_object("data")
This conf, is a dict, but pulumi correctly recognizes that inside there is a secret. if i print it shows:
{'foo': 'bar', 'priv': '[secret]'}
So i want to iterate over this dic, and do something on the secrets, but i'm not sure how to know. python thinks it is a str.
print(conf["services"]["priv"])
print(type(conf["services"]["priv"]))
[secret]
<class 'str'>
better-shampoo-48884
03/13/2021, 8:49 AMbetter-shampoo-48884
03/14/2021, 8:56 AMpulumi destroy
in such a way that I destroy all the resources in the stack that are not protected (or for which protected is not dependent on)? As it stands now I've got 19 resources, of which there are 2 protected - the resource group itself and an azure KeyVault (such a pain to pingpong it up and down). I can't do pulumi destroy because it would delete the protected resources which is not permitted. I do not feel like finding and exporting the URNs of the remaining 17 resources and chaining a --target "urn". Any other way that anyone has figured out?better-shampoo-48884
03/14/2021, 2:16 PMpulumi new azure-typescript --secrets-provider <azurekeyvault://n00531.vault.azure.net/keys/pulumi-secrets> --logflow --logtostderr --verbose 9
Results in a typical flow, and I have created the key "pulumi-secrets", and the KeyVault was created by a stack (with local secrets and backend), but trying to set up a new stack like the command above results in this:
created stack 'sdfsf'
Sorry, could not create stack 'sdfsf': secrets (code=Unknown): azure.BearerAuthorizer#WithAuthorization: Failed to refresh the Token for request to https://(myvaultname).<http://vault.azure.net/keys/pulumi-secrets//encrypt?api-version=7.0|vault.azure.net/keys/pulumi-secrets//encrypt?api-version=7.0>: StatusCode=0 -- Original Error: adal: Failed to execute the refresh request. Error = 'Get "<http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https%3A%2F%2Fvault.azure.net>": dial tcp 169.254.169.254:80: connectex: A socket operation was attempted to an unreachable network.'
I'm actually fairly curious as to where that IP for the refresh token is coming from.. I've had no such problems running pulumi up
just by being logged in by virtue of az cli..
(Edit: resolved - I did the hard work of doing everything except reading the last line of https://www.pulumi.com/docs/intro/concepts/secrets/#azure-key-vault where it tells me that if I want to use az cli auth with keyvault secrets I need to set AZURE_KEYVAULT_AUTH_VIA_CLI
to true
.)gray-nail-14734
03/14/2021, 4:00 PMAzure-Native
and trying to create an AKS cluster. All is good, until I try to set up my PodIdentityProfile
. In the AZ CLI, PodIdentity is set up in a separate step, and the Pulumi Azure-Native resource seems to follow the same paradigm. However, I can't seem to figure out how to set up my UserAssignedIdentity
after my ManagedCluster
is created. I've tried GetManagedCluster
, but the profile is an ImmutableArray
. I've tried creating a new resource (using the same name and resource group) but get a conflict.
Is there a recommended way to perform updates on existing resources? I'm looking through the Pulumi docs and don't really see this. I see how to create and destroy, but update isn't called out in many places.
BTW, I'm using C# in my scripts.
Thank you in advance for any guidance here!clever-cartoon-41433
03/14/2021, 5:16 PMbetter-shampoo-48884
03/14/2021, 5:20 PM--logflow --tracing=file:./tracefile --verbose 9
to the end of the command, then you can look through the tracefile with PULUMI_DEBUG_COMMANDS=1 pulumi view-trace ./tracefile
to see where it might be hangingbetter-shampoo-48884
03/14/2021, 5:21 PMclever-cartoon-41433
03/14/2021, 5:21 PMbetter-shampoo-48884
03/14/2021, 5:23 PM--logtostderr
to get more logs in the console.clever-cartoon-41433
03/14/2021, 5:23 PMclever-cartoon-41433
03/14/2021, 5:23 PMbetter-shampoo-48884
03/14/2021, 5:24 PMbetter-shampoo-48884
03/14/2021, 5:25 PMbetter-shampoo-48884
03/14/2021, 5:26 PMbetter-shampoo-48884
03/14/2021, 5:56 PMpulumi stack export
as well for safety, so that was good..better-shampoo-48884
03/14/2021, 5:57 PMbetter-shampoo-48884
03/14/2021, 5:57 PMbetter-shampoo-48884
03/14/2021, 6:10 PM.pulumi\stacks
directory ;))