# DynamicSecretAwsIam

> Resource DynamicSecretAwsIam in pulumi-infisical.

<!-- Generated from the pulumi-infisical SDK. -->

Resource DynamicSecretAwsIam in pulumi-infisical.

Pulumi type: `infisical:index/dynamicSecretAwsIam:DynamicSecretAwsIam`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as infisical from "pulumi-infisical"

const resource = new infisical.DynamicSecretAwsIam("dynamicSecretAwsIam", {
  configuration: {
    method: "<method>",
    region: "<region>",
  },
  defaultTtl: "<defaultTtl>",
  environmentSlug: "<environmentSlug>",
  path: "<path>",
  projectSlug: "<projectSlug>",
})
```

## Arguments

| Property           | Type                                       | Required | Description                                                  |
| ------------------ | ------------------------------------------ | -------- | ------------------------------------------------------------ |
| `configuration`    | `DynamicSecretAwsIamConfiguration (input)` | yes      | The configuration of the dynamic secret                      |
| `defaultTtl`       | `string`                                   | yes      | The default TTL that will be applied for all the leases.     |
| `environmentSlug`  | `string`                                   | yes      | The slug of the environment to create the dynamic secret in. |
| `maxTtl`           | `string`                                   | no       | The maximum limit a TTL can be leased or renewed for.        |
| `metadatas`        | `DynamicSecretAwsIamMetadata (input)[]`    | no       | The metadata associated with this dynamic secret             |
| `name`             | `string`                                   | no       | The name of the dynamic secret.                              |
| `path`             | `string`                                   | yes      | The path to create the dynamic secret in.                    |
| `projectSlug`      | `string`                                   | yes      | The slug of the project to create dynamic secret in.         |
| `usernameTemplate` | `string`                                   | no       | The username template of the dynamic secret                  |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property           | Type                                        | Computed | Description                                                  |
| ------------------ | ------------------------------------------- | -------- | ------------------------------------------------------------ |
| `configuration`    | `DynamicSecretAwsIamConfiguration (output)` | no       | The configuration of the dynamic secret                      |
| `defaultTtl`       | `string`                                    | no       | The default TTL that will be applied for all the leases.     |
| `environmentSlug`  | `string`                                    | no       | The slug of the environment to create the dynamic secret in. |
| `maxTtl`           | `string`                                    | no       | The maximum limit a TTL can be leased or renewed for.        |
| `metadatas`        | `DynamicSecretAwsIamMetadata (output)[]`    | no       | The metadata associated with this dynamic secret             |
| `name`             | `string`                                    | no       | The name of the dynamic secret.                              |
| `path`             | `string`                                    | no       | The path to create the dynamic secret in.                    |
| `projectSlug`      | `string`                                    | no       | The slug of the project to create dynamic secret in.         |
| `usernameTemplate` | `string`                                    | no       | The username template of the dynamic secret                  |

## `DynamicSecretAwsIamConfiguration (input)`

Input object `DynamicSecretAwsIamConfiguration`. Fields below belong to this object, not to the parent.

| Property                      | Type                                                       | Required | Description                                                                                                                               |
| ----------------------------- | ---------------------------------------------------------- | -------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| `accessKeyConfig`             | `DynamicSecretAwsIamConfigurationAccessKeyConfig (input)`  | no       | Configuration for the 'access_key' authentication method.                                                                                 |
| `assumeRoleConfig`            | `DynamicSecretAwsIamConfigurationAssumeRoleConfig (input)` | no       | Configuration for the 'assume_role' authentication method.                                                                                |
| `awsPath`                     | `string`                                                   | no       | IAM AWS Path to scope created IAM User resource access.                                                                                   |
| `method`                      | `string`                                                   | yes      | The authentication method to use. Must be 'access_key' or 'assume_role'.                                                                  |
| `permissionBoundaryPolicyArn` | `string`                                                   | no       | The IAM Policy ARN of the AWS Permissions Boundary to attach to IAM users created in the role.                                            |
| `policyArns`                  | `string`                                                   | no       | The AWS IAM managed policies that should be attached to the created users. Multiple values can be provided by separating them with commas |
| `policyDocument`              | `string`                                                   | no       | The AWS IAM inline policy that should be attached to the created users. Multiple values can be provided by separating them with commas    |
| `region`                      | `string`                                                   | yes      | The AWS data center region.                                                                                                               |
| `userGroups`                  | `string`                                                   | no       | The AWS IAM groups that should be assigned to the created users. Multiple values can be provided by separating them with commas           |

## `DynamicSecretAwsIamConfigurationAccessKeyConfig (input)`

Input object `DynamicSecretAwsIamConfigurationAccessKeyConfig`. Fields below belong to this object, not to the parent.

| Property          | Type     | Required | Description                          |
| ----------------- | -------- | -------- | ------------------------------------ |
| `accessKey`       | `string` | yes      | The managing AWS IAM User Access Key |
| `secretAccessKey` | `string` | yes      | The managing AWS IAM User Secret Key |

## `DynamicSecretAwsIamConfigurationAssumeRoleConfig (input)`

Input object `DynamicSecretAwsIamConfigurationAssumeRoleConfig`. Fields below belong to this object, not to the parent.

| Property  | Type     | Required | Description                        |
| --------- | -------- | -------- | ---------------------------------- |
| `roleArn` | `string` | yes      | The ARN of the AWS Role to assume. |

## `DynamicSecretAwsIamMetadata (input)`

Input object `DynamicSecretAwsIamMetadata`. Fields below belong to this object, not to the parent.

| Property | Type     | Required | Description                      |
| -------- | -------- | -------- | -------------------------------- |
| `key`    | `string` | yes      | The key of the metadata object   |
| `value`  | `string` | yes      | The value of the metadata object |

## `DynamicSecretAwsIamConfiguration (output)`

Output object `DynamicSecretAwsIamConfiguration`. Fields below belong to this object.

| Property                      | Type                                                        | Always present | Description                                                                                                                               |
| ----------------------------- | ----------------------------------------------------------- | -------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| `accessKeyConfig`             | `DynamicSecretAwsIamConfigurationAccessKeyConfig (output)`  | no             | Configuration for the 'access_key' authentication method.                                                                                 |
| `assumeRoleConfig`            | `DynamicSecretAwsIamConfigurationAssumeRoleConfig (output)` | no             | Configuration for the 'assume_role' authentication method.                                                                                |
| `awsPath`                     | `string`                                                    | no             | IAM AWS Path to scope created IAM User resource access.                                                                                   |
| `method`                      | `string`                                                    | yes            | The authentication method to use. Must be 'access_key' or 'assume_role'.                                                                  |
| `permissionBoundaryPolicyArn` | `string`                                                    | no             | The IAM Policy ARN of the AWS Permissions Boundary to attach to IAM users created in the role.                                            |
| `policyArns`                  | `string`                                                    | no             | The AWS IAM managed policies that should be attached to the created users. Multiple values can be provided by separating them with commas |
| `policyDocument`              | `string`                                                    | no             | The AWS IAM inline policy that should be attached to the created users. Multiple values can be provided by separating them with commas    |
| `region`                      | `string`                                                    | yes            | The AWS data center region.                                                                                                               |
| `userGroups`                  | `string`                                                    | no             | The AWS IAM groups that should be assigned to the created users. Multiple values can be provided by separating them with commas           |

## `DynamicSecretAwsIamConfigurationAccessKeyConfig (output)`

Output object `DynamicSecretAwsIamConfigurationAccessKeyConfig`. Fields below belong to this object.

| Property          | Type     | Always present | Description                          |
| ----------------- | -------- | -------------- | ------------------------------------ |
| `accessKey`       | `string` | yes            | The managing AWS IAM User Access Key |
| `secretAccessKey` | `string` | yes            | The managing AWS IAM User Secret Key |

## `DynamicSecretAwsIamConfigurationAssumeRoleConfig (output)`

Output object `DynamicSecretAwsIamConfigurationAssumeRoleConfig`. Fields below belong to this object.

| Property  | Type     | Always present | Description                        |
| --------- | -------- | -------------- | ---------------------------------- |
| `roleArn` | `string` | yes            | The ARN of the AWS Role to assume. |

## `DynamicSecretAwsIamMetadata (output)`

Output object `DynamicSecretAwsIamMetadata`. Fields below belong to this object.

| Property | Type     | Always present | Description                      |
| -------- | -------- | -------------- | -------------------------------- |
| `key`    | `string` | yes            | The key of the metadata object   |
| `value`  | `string` | yes            | The value of the metadata object |
