opensearch-project / opensearch-project/data-prepper

AWS Secrets plugin should notify when it is unable to read secrets

Open
#5,517 0 comments 0 reactions 1 assignee View on GitHub

@san81 is already working on this.

Since Mar 18, 2025.

enhancement
Dominant language
Java
Stars
374
Forks
354
Avg merge
3d 18h
Merged PRs (30d)
8

Description

Is your feature request related to a problem? Please describe.
When the given pipeline role doesn't have access to the aws secrets, currently, the plugin is failing to read and if this happens at the start of the pipeline, then it is crashing the pipeline start activity.

Describe the solution you'd like
Secrets Plugin should notify the source either by sending null values or with an error code (or may be both) so that Source can decide its behavior. This way, source has an opportunity to retry instead of crashing the pipeline start. Secret should also continue to poll to check if it got access to the secret and able to read and initialize the values. Existing secrets refresh logic should help implement this functionality.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.