pulumi-vault
A Pulumi package for creating and managing HashiCorp Vault cloud resources.
Decision gist · record as of 2026-08-14
Yes. Active maintenance, low install friction, permissive license, and no known vulnerabilities make it safe to adopt. Install it if you use Pulumi and need to manage Vault resources programmatically; the tight integration with Pulumi's config and secret handling is its main value. Verify that the specific Vault resource types you need are supported in this version before committing to it in production.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Pulumi CLI to be installed first and a running Vault server with valid address and authentication token (set via VAULT_ADDR and VAULT_TOKEN environment variables or Pulumi config).
- Low install friction; pure Python wheel with four lightweight runtime dependencies.
- Active maintenance with a release 3 days ago; repository shows ongoing commits and is not archived.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions; you must include a copy of the license and state significant changes.
last release 2026-08-11 (3 days) · last repo commit 2026-08-14 · 28 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 105,062 downloads/mo, #12,723 on PyPI
Alternatives
Verify before relying
pip install pulumi_vault
import pulumi
import pulumi_vault as vault
# Configure provider with Vault address and token
config = pulumi.Config()
vault_addr = config.require_secret('vault:address')
vault_token = config.require_secret('vault:token')- Specific Vault resource types and operations supported by this provider version
- Whether child token creation and TTL management work as documented in all Vault configurations
- TLS certificate authentication support status (description suggests it may not be implemented)
What it is and what it does
pulumi-vault is a Pulumi resource provider that bridges Pulumi's infrastructure-as-code framework with HashiCorp Vault, allowing you to declare and manage Vault resources (secrets engines, auth methods, policies, tokens) as part of your Pulumi stack. It requires the Pulumi CLI and a running Vault server; you authenticate by providing a Vault address and token, optionally with TLS certificate validation and namespace configuration. The provider automatically creates child tokens with limited TTL to reduce secret exposure.
You use it by installing the package, configuring your Vault connection details through Pulumi config or environment variables, and then writing Pulumi code in Python (or other supported languages) to create and manage Vault resources declaratively. It handles authentication, certificate validation, and retry logic, letting you version-control your Vault configuration alongside the rest of your infrastructure.
Use it for
- Automate Vault secret engine and auth method provisioning as part of infrastructure deployment pipelines
- Define Vault policies and token roles declaratively alongside application infrastructure in Pulumi stacks
- Manage Vault namespaces and configuration in multi-tenant or enterprise Vault deployments
- Integrate Vault secret management into GitOps workflows by storing Vault resource definitions in version control
- Programmatically configure Vault certificate authentication and TLS settings during infrastructure setup
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes.
Active maintenance, low install friction, permissive license, and no known vulnerabilities make it safe to adopt. Install it if you use Pulumi and need to manage Vault resources programmatically; the tight integration with Pulumi's config and secret handling is its main value. Verify that the specific Vault resource types you need are supported in this version before committing to it in production.
Install
pulumi-vault on PyPI
Before you install
Low install friction; pure Python wheel with four lightweight runtime dependencies. Active maintenance with a release 3 days ago; repository shows ongoing commits and is not archived.
Requires Pulumi CLI to be installed first and a running Vault server with valid address and authentication token (set via VAULT_ADDR and VAULT_TOKEN environment variables or Pulumi config).
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions; you must include a copy of the license and state significant changes.
Quickstart
pip install pulumi_vault
import pulumi
import pulumi_vault as vault
# Configure provider with Vault address and token
config = pulumi.Config()
vault_addr = config.require_secret('vault:address')
vault_token = config.require_secret('vault:token')
Verify before relying
- Specific Vault resource types and operations supported by this provider version
- Whether child token creation and TTL management work as documented in all Vault configurations
- TLS certificate authentication support status (description suggests it may not be implemented)
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.9 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 4 packagesparverpulumisemvertyping-extensions |
| Maintenance | Actively maintained 3 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 105,062 / month, #12,723 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
Evidence: pulumi_vault-7.11.1-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “pulumi vault provider”
- pulumi-vaultPulumi resource provider for HashiCorp Vault that lets you define and…
- pulumi-azurePulumi provider for Azure Classic that lets you define and manage…
- pulumiverse-timeA Pulumi resource provider that lets you manage time-based resources…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also pulumi-tls · pulumi-docker · saltext.vault · pulumi-postgresql · pulumi-gitlab · pulumi-datadog · pulumi-pulumiservice · pulumi-github · hvac · pulumi-keycloak