creamy-beard-50597
01/03/2025, 11:58 AMdef add_secret(name: str, value: Union[str, dict], description: str):
"""Function to add a secret to AWS"""
secret = aws.secretsmanager.Secret(
resource_name=name,
name=name,
description=description,
)
aws.secretsmanager.SecretVersion(
f"secret-version/{name}",
secret_id=secret.id,
secret_string=value,
)
aws:secretsmanager:SecretVersion (secret-version/production-xxxx-platform-xxxx-api-token):
error: sdk-v2/provider2.go:515: sdk.helper_schema: deleting Secrets Manager Secret Version (arn:aws:secretsmanager:eu-central-1:xxxx:secret:production-xxxx-platform-xxxx-api-token-Mjdgew|terraform-20250103102936863100000009) stage (AWSPREVIOUS): operation error Secrets Manager: UpdateSecretVersionStage, https response error StatusCode: 400, RequestID: 532437ac-b9a3-4460-bb0c-a60fa8ce552d, InvalidParameterException: When you move staging label AWSPREVIOUS, if you specify RemoveFromVersionId, it must be set to the version that currently has the staging label terraform-20250103114221271600000009.: provider=aws@6.66.2
error: deleting urn:pulumi:production::platform-platform::aws:secretsmanager/secretVersion:SecretVersion::secret-version/production-xxx-platform-xxxx-api-token: 1 error occurred:
* deleting Secrets Manager Secret Version (arn:aws:secretsmanager:eu-central-1:495775544086:secret:production-xxxx-platform-xxxx-api-token-Mjdgew|terraform-20250103102936863100000009) stage (AWSPREVIOUS): operation error Secrets Manager: UpdateSecretVersionStage, https response error StatusCode: 400, RequestID: 532437ac-b9a3-4460-bb0c-a60fa8ce552d, InvalidParameterException: When you move staging label AWSPREVIOUS, if you specify RemoveFromVersionId, it must be set to the version that currently has the staging label terraform-20250103114221271600000009.
quick-house-41860
01/03/2025, 3:05 PMcreamy-beard-50597
01/03/2025, 3:07 PMpulumi_aws
6.59
and now using the latestcreamy-beard-50597
01/03/2025, 3:37 PMcreamy-beard-50597
01/03/2025, 3:54 PMcreate-replacement
-> AWSCURRENT version is replaced
> delete original
( and here it fails at updating the AWSPREVIOUS value )quick-house-41860
01/03/2025, 4:33 PMcreamy-beard-50597
01/03/2025, 4:34 PMquick-house-41860
01/03/2025, 7:59 PMAWSPREVIOUS
label being moved away from the old/replaced version before it's getting deleted.
If you manage to create a repro for this please cut an issue here so that we can further dig into it!