Skip to main content

CertManagerCertificate

Resource CertManagerCertificate in pulumi-infisical.
4 min read

Resource CertManagerCertificate in pulumi-infisical.

Pulumi type: infisical:index/certManagerCertificate:CertManagerCertificate.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
altNamesstring[]noSubject alternative names (SANs) for the certificate
applicationIdstringyesThe ID of the Certificate Manager application to issue this certificate from
commonNamestringnoThe common name (CN) for the certificate. Required when not using CSR
countrystringnoThe country (C) for the certificate (2-letter code)
csrstringnoCertificate Signing Request (CSR) in PEM format. If provided, the certificate will be issued based on the CSR. Use Terraform's file() function to read from a file (e.g., file("./my-certificate.csr")).
domainComponentsstring[]noDomain components (DC) for the certificate. Multi-valued; each entry becomes a DC attribute in the subject.
extendedKeyUsagesstring[]noExtended key usages for the certificate. Supported: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping
keyAlgorithmstringnoThe key algorithm for the certificate. Supported: RSA_2048, RSA_3072, RSA_4096, EC_prime256v1, EC_secp384r1, EC_secp521r1
keyUsagesstring[]noKey usages for the certificate. Supported: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only
localitystringnoThe locality (L) for the certificate
organizationstringnoThe organization (O) for the certificate
oustringnoThe organizational unit (OU) for the certificate
profileIdstringyesThe ID of the certificate profile to use for issuance
provincestringnoThe state/province (ST) for the certificate
signatureAlgorithmstringnoThe signature algorithm for the certificate. Supported: RSA-SHA256, RSA-SHA384, RSA-SHA512, ECDSA-SHA256, ECDSA-SHA384, ECDSA-SHA512
timeoutSecondsnumbernoMaximum time to wait for certificate issuance in seconds. Defaults to 3600 (1 hour)
ttlstringnoTime to live for the certificate (e.g., '30d', '90d', '1y').

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
altNamesstring[]noSubject alternative names (SANs) for the certificate
applicationIdstringnoThe ID of the Certificate Manager application to issue this certificate from
certificatestringyesThe issued certificate in PEM format.
certificateChainstringyesThe certificate chain in PEM format.
certificateRequestIdstringyesThe ID of the certificate request
commonNamestringnoThe common name (CN) for the certificate. Required when not using CSR
countrystringnoThe country (C) for the certificate (2-letter code)
csrstringnoCertificate Signing Request (CSR) in PEM format. If provided, the certificate will be issued based on the CSR. Use Terraform's file() function to read from a file (e.g., file("./my-certificate.csr")).
domainComponentsstring[]noDomain components (DC) for the certificate. Multi-valued; each entry becomes a DC attribute in the subject.
extendedKeyUsagesstring[]noExtended key usages for the certificate. Supported: client_auth, server_auth, code_signing, email_protection, ocsp_signing, time_stamping
keyAlgorithmstringnoThe key algorithm for the certificate. Supported: RSA_2048, RSA_3072, RSA_4096, EC_prime256v1, EC_secp384r1, EC_secp521r1
keyUsagesstring[]noKey usages for the certificate. Supported: digital_signature, key_encipherment, non_repudiation, data_encipherment, key_agreement, key_cert_sign, crl_sign, encipher_only, decipher_only
localitystringnoThe locality (L) for the certificate
notAfterstringyesThe not-after (expiration) date of the certificate (RFC3339 format)
notBeforestringyesThe not-before date of the certificate (RFC3339 format)
organizationstringnoThe organization (O) for the certificate
oustringnoThe organizational unit (OU) for the certificate
privateKeystringyesThe private key in PEM format (only available for direct field requests, not CSR-based).
profileIdstringnoThe ID of the certificate profile to use for issuance
provincestringnoThe state/province (ST) for the certificate
serialNumberstringyesThe serial number of the issued certificate
signatureAlgorithmstringnoThe signature algorithm for the certificate. Supported: RSA-SHA256, RSA-SHA384, RSA-SHA512, ECDSA-SHA256, ECDSA-SHA384, ECDSA-SHA512
statusstringyesThe status of the certificate (pending, issued, failed)
timeoutSecondsnumbernoMaximum time to wait for certificate issuance in seconds. Defaults to 3600 (1 hour)
ttlstringnoTime to live for the certificate (e.g., '30d', '90d', '1y').