arazzo: 1.0.1
info:
title: Amazon Secrets Manager Tag Secret and Verify
summary: Attach tags to a secret with TagResource, then describe the secret to confirm the tags are present in its metadata.
description: >-
The metadata governance pattern. The workflow attaches a set of key/value
tags to a secret so it can be tracked for cost allocation, ownership, or
access control, then calls DescribeSecret to read the Tags back and confirm
they were applied. Every step inlines the AWS JSON 1.1 X-Amz-Target header
and request payload so the flow is self-describing.
version: 1.0.0
x-realizes-capability-ids:
- BC-620.20
x-capability-derivation:
method: 'deterministic join: sourceDescriptions -> per-tag OpenAPI -> tag/capability edge. No classification at this step.'
min_confidence: 0.7
sources:
- capability_id: BC-620.20
capability_name: Identity & Access Management
spec: amazon-secrets-manager-secrets-api-openapi.yml
confidence: 0.8
model: Turbo EA Capabilities by Vincent Verdet — Turbo EA, https://github.com/vincentmakes/turbo-ea-capabilities, CC BY 4.0
sourceDescriptions:
- name: secretsApi
url: ../openapi/amazon-secrets-manager-secrets-api-openapi.yml
type: openapi
- name: tagresourceApi
url: ../openapi/amazon-secrets-manager-tagresource-api-openapi.yml
type: openapi
workflows:
- workflowId: tag-secret-and-verify
summary: Apply tags to a secret and confirm they appear in its metadata.
description: >-
Calls TagResource to attach the supplied tags to a secret, then calls
DescribeSecret to verify the tags are present in the secret's metadata.
inputs:
type: object
required:
- SecretId
- Tags
properties:
SecretId:
type: string
description: The ARN or name of the secret to tag.
Tags:
type: array
description: A list of Key/Value tag objects to attach to the secret.
items:
type: object
properties:
Key:
type: string
Value:
type: string
steps:
- stepId: tagResource
description: >-
Attach the supplied key/value tags to the secret's metadata.
operationId: TagResource
parameters:
- name: X-Amz-Target
in: header
value: secretsmanager.TagResource
requestBody:
contentType: application/x-amz-json-1.1
payload:
SecretId: $inputs.SecretId
Tags: $inputs.Tags
successCriteria:
- condition: $statusCode == 200
- stepId: describeSecret
description: >-
Read the secret metadata back to confirm the tags were applied.
operationId: DescribeSecret
parameters:
- name: X-Amz-Target
in: header
value: secretsmanager.DescribeSecret
requestBody:
contentType: application/x-amz-json-1.1
payload:
SecretId: $inputs.SecretId
successCriteria:
- condition: $statusCode == 200
outputs:
secretArn: $response.body#/ARN
tags: $response.body#/Tags
outputs:
secretArn: $steps.describeSecret.outputs.secretArn
tags: $steps.describeSecret.outputs.tags
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we
store it to create your key and to recognise you if you sign in with another
provider. See our Privacy Policy and
Terms.