A serverless secrets manager demo using Pulumi ESC (AWS) was built to securely retrieve and inject environment variables into a Lambda function.
The project demonstrates secure storage of secrets in Pulumi ESC, fetching secrets programmatically via the Pulumi SDK, injecting secrets into cloud resources without exposing them in code, and implementing least-privilege IAM policies.
Key files include __main__.py, secrets-manager.tf, and README.md which contains a full setup guide and security practices.
Pulumi ESC provides centralized secrets management for multi-cloud apps, built-in rotation policies, and auditing capabilities via CloudTrail.