Configuration for pulumi-infisical.
npm package pulumi-infisical version 0.20.6.
Pulumi bridge terraform-provider version 1.4.0.
Upstream provider registry.opentofu.org/infisical/infisical version 0.19.36.
An explicit provider is new infisical.Provider(name, args). Stack configuration is a pulumi.Config object named infisical.
A value marked secret is passed through pulumi.secret or listed in additionalSecretOutputs on the provider resource.
Fields#
| Property | Type | Source | Secret | Description |
|---|---|---|---|---|
auth | ProviderAuth | provider args; stack config via config.getObject | no | The configuration values for authentication |
clientId | string | provider args; stack config via config.get | yes | (DEPRECATED, Use the auth attribute), Machine identity client ID. Used to fetch/modify secrets for a given project. |
clientSecret | string | provider args; stack config via config.get | yes | (DEPRECATED, use auth attribute), Machine identity client secret. Used to fetch/modify secrets for a given project |
host | string | provider args; stack config via config.get | no | Used to point the client to fetch secrets from your self hosted instance of Infisical. If not host is provided, https://app.infisical.com is the default host. This attribute can also be set using the INFISICAL_HOST environment variable |
serviceToken | string | provider args; stack config via config.get | yes | (DEPRECATED, Use machine identity auth), Used to fetch/modify secrets for a given project |
ProviderAuth#
Input object ProviderAuth. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
awsIam | ProviderAuthAwsIam | no | The configuration values for AWS IAM Auth |
kubernetes | ProviderAuthKubernetes | no | The configuration values for Kubernetes Auth |
oidc | ProviderAuthOidc | no | The configuration values for OIDC Auth |
organizationSlug | string | no | When set, this will scope the login session to the specified organization the machine identity has access to. If left empty, the session defaults to the organization where the machine identity was created in. |
token | string | no | The authentication token for Machine Identity Token Auth. This attribute can also be set using the INFISICAL_TOKEN environment variable |
universal | ProviderAuthUniversal | no | The configuration values for Universal Auth |
ProviderAuthAwsIam#
Input object ProviderAuthAwsIam. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
identityId | string | no | Machine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable |
ProviderAuthKubernetes#
Input object ProviderAuthKubernetes. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
identityId | string | no | Machine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable |
serviceAccountToken | string | no | The service account token. This attribute can also be set using the INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN environment variable |
serviceAccountTokenPath | string | no | The path to the service account token. This attribute can also be set using the INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH environment variable. Default is /var/run/secrets/kubernetes.io/serviceaccount/token. |
ProviderAuthOidc#
Input object ProviderAuthOidc. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
identityId | string | no | Machine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable |
tokenEnvironmentVariableName | string | no | The environment variable name for the OIDC JWT token. This attribute can also be set using the INFISICAL_OIDC_AUTH_TOKEN_KEY_NAME environment variable. Default is INFISICAL_AUTH_JWT. |
ProviderAuthUniversal#
Input object ProviderAuthUniversal. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
clientId | string | no | Machine identity client ID. This attribute can also be set using the INFISICAL_UNIVERSAL_AUTH_CLIENT_ID environment variable |
clientSecret | string | no | Machine identity client secret. This attribute can also be set using the INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET environment variable |
config.Auth#
Output object config.Auth. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
awsIam | config.AuthAwsIam | no | The configuration values for AWS IAM Auth |
kubernetes | config.AuthKubernetes | no | The configuration values for Kubernetes Auth |
oidc | config.AuthOidc | no | The configuration values for OIDC Auth |
organizationSlug | string | no | When set, this will scope the login session to the specified organization the machine identity has access to. If left empty, the session defaults to the organization where the machine identity was created in. |
token | string | no | The authentication token for Machine Identity Token Auth. This attribute can also be set using the INFISICAL_TOKEN environment variable |
universal | config.AuthUniversal | no | The configuration values for Universal Auth |
config.AuthAwsIam#
Output object config.AuthAwsIam. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
identityId | string | no | Machine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable |
config.AuthKubernetes#
Output object config.AuthKubernetes. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
identityId | string | no | Machine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable |
serviceAccountToken | string | no | The service account token. This attribute can also be set using the INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN environment variable |
serviceAccountTokenPath | string | no | The path to the service account token. This attribute can also be set using the INFISICAL_KUBERNETES_SERVICE_ACCOUNT_TOKEN_PATH environment variable. Default is /var/run/secrets/kubernetes.io/serviceaccount/token. |
config.AuthOidc#
Output object config.AuthOidc. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
identityId | string | no | Machine identity ID. This attribute can also be set using the INFISICAL_MACHINE_IDENTITY_ID environment variable |
tokenEnvironmentVariableName | string | no | The environment variable name for the OIDC JWT token. This attribute can also be set using the INFISICAL_OIDC_AUTH_TOKEN_KEY_NAME environment variable. Default is INFISICAL_AUTH_JWT. |
config.AuthUniversal#
Output object config.AuthUniversal. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
clientId | string | no | Machine identity client ID. This attribute can also be set using the INFISICAL_UNIVERSAL_AUTH_CLIENT_ID environment variable |
clientSecret | string | no | Machine identity client secret. This attribute can also be set using the INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET environment variable |