Resource CertManagerCertificate in pulumi-infisical.
Pulumi type: infisical:index/certManagerCertificate:CertManagerCertificate.
name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.
Example#
Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.
Arguments#
| Property | Type | Required | Description |
|---|---|---|---|
altNames | string[] | no | Subject alternative names (SANs) for the certificate |
applicationId | string | yes | The ID of the Certificate Manager application to issue this certificate from |
commonName | string | no | The common name (CN) for the certificate. Required when not using CSR |
country | string | no | The country (C) for the certificate (2-letter code) |
csr | string | no | Certificate Signing Request (CSR) in PEM format. If provided, the certificate will be issued based on the CSR. Use Terraform's file() function to read from a file (e.g., file("./my-certificate.csr")). |
domainComponents | string[] | no | Domain components (DC) for the certificate. Multi-valued; each entry becomes a DC attribute in the subject. |
extendedKeyUsages | string[] | no | Extended key usages for the certificate. Supported: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping |
keyAlgorithm | string | no | The key algorithm for the certificate. Supported: RSA_2048, RSA_3072, RSA_4096, EC_prime256v1, EC_secp384r1, EC_secp521r1 |
keyUsages | string[] | no | Key usages for the certificate. Supported: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only |
locality | string | no | The locality (L) for the certificate |
organization | string | no | The organization (O) for the certificate |
ou | string | no | The organizational unit (OU) for the certificate |
profileId | string | yes | The ID of the certificate profile to use for issuance |
province | string | no | The state/province (ST) for the certificate |
signatureAlgorithm | string | no | The signature algorithm for the certificate. Supported: RSA-SHA256, RSA-SHA384, RSA-SHA512, ECDSA-SHA256, ECDSA-SHA384, ECDSA-SHA512 |
timeoutSeconds | number | no | Maximum time to wait for certificate issuance in seconds. Defaults to 3600 (1 hour) |
ttl | string | no | Time to live for the certificate (e.g., '30d', '90d', '1y'). |
Outputs#
Computed outputs are produced by the provider. They are not constructor arguments.
| Property | Type | Computed | Description |
|---|---|---|---|
altNames | string[] | no | Subject alternative names (SANs) for the certificate |
applicationId | string | no | The ID of the Certificate Manager application to issue this certificate from |
certificate | string | yes | The issued certificate in PEM format. |
certificateChain | string | yes | The certificate chain in PEM format. |
certificateRequestId | string | yes | The ID of the certificate request |
commonName | string | no | The common name (CN) for the certificate. Required when not using CSR |
country | string | no | The country (C) for the certificate (2-letter code) |
csr | string | no | Certificate Signing Request (CSR) in PEM format. If provided, the certificate will be issued based on the CSR. Use Terraform's file() function to read from a file (e.g., file("./my-certificate.csr")). |
domainComponents | string[] | no | Domain components (DC) for the certificate. Multi-valued; each entry becomes a DC attribute in the subject. |
extendedKeyUsages | string[] | no | Extended key usages for the certificate. Supported: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping |
keyAlgorithm | string | no | The key algorithm for the certificate. Supported: RSA_2048, RSA_3072, RSA_4096, EC_prime256v1, EC_secp384r1, EC_secp521r1 |
keyUsages | string[] | no | Key usages for the certificate. Supported: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only |
locality | string | no | The locality (L) for the certificate |
notAfter | string | yes | The not-after (expiration) date of the certificate (RFC3339 format) |
notBefore | string | yes | The not-before date of the certificate (RFC3339 format) |
organization | string | no | The organization (O) for the certificate |
ou | string | no | The organizational unit (OU) for the certificate |
privateKey | string | yes | The private key in PEM format (only available for direct field requests, not CSR-based). |
profileId | string | no | The ID of the certificate profile to use for issuance |
province | string | no | The state/province (ST) for the certificate |
serialNumber | string | yes | The serial number of the issued certificate |
signatureAlgorithm | string | no | The signature algorithm for the certificate. Supported: RSA-SHA256, RSA-SHA384, RSA-SHA512, ECDSA-SHA256, ECDSA-SHA384, ECDSA-SHA512 |
status | string | yes | The status of the certificate (pending, issued, failed) |
timeoutSeconds | number | no | Maximum time to wait for certificate issuance in seconds. Defaults to 3600 (1 hour) |
ttl | string | no | Time to live for the certificate (e.g., '30d', '90d', '1y'). |