airflow.providers.google.cloud.hooks.secret_manager

Hook for Secrets Manager service.

Module Contents

Classes

SecretsManagerHook

Hook for the Google Secret Manager API.

class airflow.providers.google.cloud.hooks.secret_manager.SecretsManagerHook(gcp_conn_id='google_cloud_default', impersonation_chain=None, **kwargs)[source]

Bases: airflow.providers.google.common.hooks.base_google.GoogleBaseHook

Hook for the Google Secret Manager API.

See https://cloud.google.com/secret-manager

All the methods in the hook where project_id is used must be called with keyword arguments rather than positional.

Parameters
  • gcp_conn_id (str) – The connection ID to use when fetching connection info.

  • impersonation_chain (str | Sequence[str] | None) – Optional service account to impersonate using short-term credentials, or chained list of accounts required to get the access_token of the last account in the list, which will be impersonated in the request. If set as a string, the account must grant the originating account the Service Account Token Creator IAM role. If set as a sequence, the identities from the list must grant Service Account Token Creator IAM role to the directly preceding identity, with first account from the list granting this role to the originating account.

get_conn()[source]

Retrieve the connection to Secret Manager.

Returns

Secret Manager client.

Return type

airflow.providers.google.cloud._internal_client.secret_manager_client._SecretManagerClient

get_secret(secret_id, secret_version='latest', project_id=None)[source]

Get secret value from the Secret Manager.

Parameters
  • secret_id (str) – Secret Key

  • secret_version (str) – version of the secret (default is ‘latest’)

  • project_id (str | None) – Project id (if you want to override the project_id from credentials)

Was this entry helpful?