Skip to main content

Configuration

Configuration for pulumi-infisical.
6 min read

Configuration for pulumi-infisical.

npm package pulumi-infisical version 0.20.6. Pulumi bridge terraform-provider version 1.4.0. Upstream provider registry.opentofu.org/infisical/infisical version 0.19.36.

An explicit provider is new infisical.Provider(name, args). Stack configuration is a pulumi.Config object named infisical.

A value marked secret is passed through pulumi.secret or listed in additionalSecretOutputs on the provider resource.

Fields#

PropertyTypeSourceSecretDescription
authProviderAuthprovider args; stack config via config.getObjectnoThe configuration values for authentication
clientIdstringprovider args; stack config via config.getyes(DEPRECATED, Use the auth attribute), Machine identity client ID. Used to fetch/modify secrets for a given project.
clientSecretstringprovider args; stack config via config.getyes(DEPRECATED, use auth attribute), Machine identity client secret. Used to fetch/modify secrets for a given project
hoststringprovider args; stack config via config.getnoUsed to point the client to fetch secrets from your self hosted instance of Infisical. If not host is provided, https://app.infisical.com is the default host. This attribute can also be set using the INFISICAL_HOST environment variable
serviceTokenstringprovider args; stack config via config.getyes(DEPRECATED, Use machine identity auth), Used to fetch/modify secrets for a given project

ProviderAuth#

Input object ProviderAuth. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
awsIamProviderAuthAwsIamnoThe configuration values for AWS IAM Auth
kubernetesProviderAuthKubernetesnoThe configuration values for Kubernetes Auth
oidcProviderAuthOidcnoThe configuration values for OIDC Auth
organizationSlugstringnoWhen set, this will scope the login session to the specified organization the machine identity has access to. If left empty, the session defaults to the organization where the machine identity was created in.
tokenstringnoThe authentication token for Machine Identity Token Auth. This attribute can also be set using the INFISICAL_TOKEN environment variable
universalProviderAuthUniversalnoThe configuration values for Universal Auth

ProviderAuthAwsIam#

Input object ProviderAuthAwsIam. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
identityIdstringnoMachine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable

ProviderAuthKubernetes#

Input object ProviderAuthKubernetes. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
identityIdstringnoMachine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable
serviceAccountTokenstringnoThe service account token. This attribute can also be set using the INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN environment variable
serviceAccountTokenPathstringnoThe path to the service account token. This attribute can also be set using the INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH environment variable. Default is /var/run/secrets/kubernetes.io/serviceaccount/token.

ProviderAuthOidc#

Input object ProviderAuthOidc. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
identityIdstringnoMachine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable
tokenEnvironmentVariableNamestringnoThe environment variable name for the OIDC JWT token. This attribute can also be set using the INFISICAL_OIDC_AUTH_TOKEN_KEY_NAME environment variable. Default is INFISICAL_AUTH_JWT.

ProviderAuthUniversal#

Input object ProviderAuthUniversal. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
clientIdstringnoMachine identity client ID. This attribute can also be set using the INFISICAL_UNIVERSAL_AUTH_CLIENT_ID environment variable
clientSecretstringnoMachine identity client secret. This attribute can also be set using the INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET environment variable

config.Auth#

Output object config.Auth. Fields below belong to this object.

PropertyTypeAlways presentDescription
awsIamconfig.AuthAwsIamnoThe configuration values for AWS IAM Auth
kubernetesconfig.AuthKubernetesnoThe configuration values for Kubernetes Auth
oidcconfig.AuthOidcnoThe configuration values for OIDC Auth
organizationSlugstringnoWhen set, this will scope the login session to the specified organization the machine identity has access to. If left empty, the session defaults to the organization where the machine identity was created in.
tokenstringnoThe authentication token for Machine Identity Token Auth. This attribute can also be set using the INFISICAL_TOKEN environment variable
universalconfig.AuthUniversalnoThe configuration values for Universal Auth

config.AuthAwsIam#

Output object config.AuthAwsIam. Fields below belong to this object.

PropertyTypeAlways presentDescription
identityIdstringnoMachine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable

config.AuthKubernetes#

Output object config.AuthKubernetes. Fields below belong to this object.

PropertyTypeAlways presentDescription
identityIdstringnoMachine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable
serviceAccountTokenstringnoThe service account token. This attribute can also be set using the INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN environment variable
serviceAccountTokenPathstringnoThe path to the service account token. This attribute can also be set using the INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH environment variable. Default is /var/run/secrets/kubernetes.io/serviceaccount/token.

config.AuthOidc#

Output object config.AuthOidc. Fields below belong to this object.

PropertyTypeAlways presentDescription
identityIdstringnoMachine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable
tokenEnvironmentVariableNamestringnoThe environment variable name for the OIDC JWT token. This attribute can also be set using the INFISICAL_OIDC_AUTH_TOKEN_KEY_NAME environment variable. Default is INFISICAL_AUTH_JWT.

config.AuthUniversal#

Output object config.AuthUniversal. Fields below belong to this object.

PropertyTypeAlways presentDescription
clientIdstringnoMachine identity client ID. This attribute can also be set using the INFISICAL_UNIVERSAL_AUTH_CLIENT_ID environment variable
clientSecretstringnoMachine identity client secret. This attribute can also be set using the INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET environment variable