Big News: Socket raises $60M Series C at a $1B valuation to secure software supply chains for AI-driven development.Announcement
Sign In

@lockzero/aws-sync

Package Overview
Dependencies
Maintainers
1
Versions
1
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@lockzero/aws-sync

Bidirectional sync between LockZero and AWS Secrets Manager / SSM Parameter Store

latest
Source
npmnpm
Version
1.0.0
Version published
Weekly downloads
5
Maintainers
1
Weekly downloads
 
Created
Source

@lockzero/aws-sync

Bidirectional sync between LockZero and AWS Secrets Manager / SSM Parameter Store.

Installation

npm install -g @lockzero/aws-sync
# or as a dev dependency
npm install --save-dev @lockzero/aws-sync

Authentication

CredentialHow to provide
LockZero API key--lz-key <key> or LOCKZERO_API_KEY env var
AWS credentialsStandard AWS SDK chain: env vars, ~/.aws/credentials, OIDC, instance profile

Commands

push — LockZero → AWS

# Push the "openai" namespace to SSM Parameter Store
lockzero-aws push --namespace openai --backend ssm --prefix /lockzero/

# Push to Secrets Manager instead
lockzero-aws push --namespace openai --backend secretsmanager --prefix /lockzero/

# Preview without writing
lockzero-aws push --namespace openai --backend ssm --prefix /lockzero/ --dry-run

SSM parameters are created as SecureString at path <prefix><namespace>/<fieldKey>.
Secrets Manager stores all fields as a JSON blob in one secret named <prefix><namespace>.

pull — AWS → LockZero

# Pull SSM parameters back into LockZero
lockzero-aws pull --namespace openai --backend ssm --prefix /lockzero/

# Preview without writing
lockzero-aws pull --namespace openai --backend ssm --prefix /lockzero/ --dry-run

diff — show what would change

# Show what a push would do
lockzero-aws diff --namespace openai --backend ssm --prefix /lockzero/ --direction push

# Show what a pull would do
lockzero-aws diff --namespace openai --backend ssm --prefix /lockzero/ --direction pull

Output is color-coded: green + = add, yellow ~ = update, red - = orphan, gray = = unchanged.

GitHub Actions

See src/examples/sync-workflow.yml for a complete CI workflow using OIDC (no static AWS keys needed).

Options

FlagDefaultDescription
--namespacerequiredLockZero namespace (e.g. openai, stripe)
--backendssmssm or secretsmanager
--prefix/lockzero/Path prefix for AWS parameters/secrets
--lz-keyenvLockZero API key
--lz-base-urlhttps://api.lockzero.ioLockZero base URL
--regionenvAWS region
--dry-runfalsePreview changes without writing

Keywords

lockzero

FAQs

Package last updated on 10 May 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts