Skip to main content

AccessApprovalPolicy

Resource AccessApprovalPolicy in pulumi-infisical.
4 min read

Resource AccessApprovalPolicy in pulumi-infisical.

Pulumi type: infisical:index/accessApprovalPolicy:AccessApprovalPolicy.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
allowSelfApprovalbooleannoWhether to allow approvers to approve their own requests
approversAccessApprovalPolicyApprover (input)[]yesThe required approvers
bypassersAccessApprovalPolicyBypasser (input)[]noThe bypassers who can bypass the approval policy
enforcementLevelstringnoThe enforcement level of the policy. This can either be hard or soft
environmentSlugstringno(DEPRECATED, Use environmentSlugs instead) The environment to apply the access approval policy to
environmentSlugsstring[]noThe environments to apply the access approval policy to
maxTimePeriodstringnoThe maximum time period for the access approval, specified as a duration string (e.g. '1h', '30m', '2d'). If omitted, the default behavior is 'permanent'.
namestringnoThe name of the access approval policy
projectIdstringyesThe ID of the project to add the access approval policy
requestExpirationTimestringnoThe time after which the access request expires, specified as a duration string (e.g. '1h', '3d', '72h'). Must be between 1 minute and 1 year. If omitted, the default behavior is 'never'.
requiredApprovalsnumberyesThe number of required approvers
secretPathstringyesThe secret path to apply the access approval policy to

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
allowSelfApprovalbooleannoWhether to allow approvers to approve their own requests
approversAccessApprovalPolicyApprover (output)[]noThe required approvers
bypassersAccessApprovalPolicyBypasser (output)[]noThe bypassers who can bypass the approval policy
enforcementLevelstringnoThe enforcement level of the policy. This can either be hard or soft
environmentSlugstringno(DEPRECATED, Use environmentSlugs instead) The environment to apply the access approval policy to
environmentSlugsstring[]noThe environments to apply the access approval policy to
maxTimePeriodstringnoThe maximum time period for the access approval, specified as a duration string (e.g. '1h', '30m', '2d'). If omitted, the default behavior is 'permanent'.
namestringnoThe name of the access approval policy
projectIdstringnoThe ID of the project to add the access approval policy
requestExpirationTimestringnoThe time after which the access request expires, specified as a duration string (e.g. '1h', '3d', '72h'). Must be between 1 minute and 1 year. If omitted, the default behavior is 'never'.
requiredApprovalsnumbernoThe number of required approvers
secretPathstringnoThe secret path to apply the access approval policy to

AccessApprovalPolicyApprover (input)#

Input object AccessApprovalPolicyApprover. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
idstringnoThe ID of the approver
typestringyesThe type of approver. Either group or user
usernamestringnoThe username of the approver. By default, this is the email

AccessApprovalPolicyBypasser (input)#

Input object AccessApprovalPolicyBypasser. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
idstringnoThe ID of the bypasser
typestringyesThe type of bypasser. Either group or user
usernamestringnoThe username of the bypasser. By default, this is the email

AccessApprovalPolicyApprover (output)#

Output object AccessApprovalPolicyApprover. Fields below belong to this object.

PropertyTypeAlways presentDescription
idstringnoThe ID of the approver
typestringyesThe type of approver. Either group or user
usernamestringnoThe username of the approver. By default, this is the email

AccessApprovalPolicyBypasser (output)#

Output object AccessApprovalPolicyBypasser. Fields below belong to this object.

PropertyTypeAlways presentDescription
idstringnoThe ID of the bypasser
typestringyesThe type of bypasser. Either group or user
usernamestringnoThe username of the bypasser. By default, this is the email