Resource DynamicSecretKubernetes in pulumi-infisical.
Pulumi type: infisical:index/dynamicSecretKubernetes:DynamicSecretKubernetes.
name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.
Example#
Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.
Arguments#
| Property | Type | Required | Description |
|---|---|---|---|
configuration | DynamicSecretKubernetesConfiguration (input) | yes | The configuration of the dynamic secret |
defaultTtl | string | yes | The default TTL that will be applied for all the leases. |
environmentSlug | string | yes | The slug of the environment to create the dynamic secret in. |
maxTtl | string | no | The maximum limit a TTL can be leased or renewed for. |
metadatas | DynamicSecretKubernetesMetadata (input)[] | no | The metadata associated with this dynamic secret |
name | string | no | The name of the dynamic secret. |
path | string | yes | The path to create the dynamic secret in. |
projectSlug | string | yes | The slug of the project to create dynamic secret in. |
usernameTemplate | string | no | The username template of the dynamic secret |
Outputs#
Computed outputs are produced by the provider. They are not constructor arguments.
| Property | Type | Computed | Description |
|---|---|---|---|
configuration | DynamicSecretKubernetesConfiguration (output) | no | The configuration of the dynamic secret |
defaultTtl | string | no | The default TTL that will be applied for all the leases. |
environmentSlug | string | no | The slug of the environment to create the dynamic secret in. |
maxTtl | string | no | The maximum limit a TTL can be leased or renewed for. |
metadatas | DynamicSecretKubernetesMetadata (output)[] | no | The metadata associated with this dynamic secret |
name | string | no | The name of the dynamic secret. |
path | string | no | The path to create the dynamic secret in. |
projectSlug | string | no | The slug of the project to create dynamic secret in. |
usernameTemplate | string | no | The username template of the dynamic secret |
DynamicSecretKubernetesConfiguration (input)#
Input object DynamicSecretKubernetesConfiguration. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
apiConfig | DynamicSecretKubernetesConfigurationApiConfig (input) | no | Configuration for the 'api' authentication method. |
audiences | string[] | no | Optional list of audiences to include in the generated token. |
authMethod | string | yes | Choose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster. |
credentialType | string | yes | Choose between 'static' (predefined service account) or 'dynamic' (temporary service accounts with role assignments). |
dynamicConfig | DynamicSecretKubernetesConfigurationDynamicConfig (input) | no | Configuration for the 'dynamic' credential type. |
gatewayId | string | no | Select a gateway for private cluster access. If not specified, the Internet Gateway will be used. |
staticConfig | DynamicSecretKubernetesConfigurationStaticConfig (input) | no | Configuration for the 'static' credential type. |
DynamicSecretKubernetesConfigurationApiConfig (input)#
Input object DynamicSecretKubernetesConfigurationApiConfig. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
ca | string | no | Custom CA certificate for the Kubernetes API server. Leave blank to use the system/public CA. |
clusterToken | string | yes | Service account token with permissions to create service accounts and manage RBAC. |
clusterUrl | string | yes | Kubernetes API server URL (e.g., https://kubernetes.default.svc). |
enableSsl | boolean | no | Whether to enable SSL verification for the Kubernetes API server connection. |
DynamicSecretKubernetesConfigurationDynamicConfig (input)#
Input object DynamicSecretKubernetesConfigurationDynamicConfig. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
allowedNamespaces | string | yes | Kubernetes namespace(s) where the service accounts will be created. You can specify multiple namespaces as a comma-separated list (e.g., “default,kube-system”). During lease creation, you can specify which namespace to use from this allowed list. |
role | string | yes | Name of the role to assign to the temporary service account. |
roleType | string | yes | Type of role to assign ('cluster-role' or 'role'). |
DynamicSecretKubernetesConfigurationStaticConfig (input)#
Input object DynamicSecretKubernetesConfigurationStaticConfig. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
namespace | string | yes | Kubernetes namespace where the service account exists. |
serviceAccountName | string | yes | Name of the service account to generate tokens for. |
DynamicSecretKubernetesMetadata (input)#
Input object DynamicSecretKubernetesMetadata. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
key | string | yes | The key of the metadata object |
value | string | yes | The value of the metadata object |
DynamicSecretKubernetesConfiguration (output)#
Output object DynamicSecretKubernetesConfiguration. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
apiConfig | DynamicSecretKubernetesConfigurationApiConfig (output) | no | Configuration for the 'api' authentication method. |
audiences | string[] | no | Optional list of audiences to include in the generated token. |
authMethod | string | yes | Choose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster. |
credentialType | string | yes | Choose between 'static' (predefined service account) or 'dynamic' (temporary service accounts with role assignments). |
dynamicConfig | DynamicSecretKubernetesConfigurationDynamicConfig (output) | no | Configuration for the 'dynamic' credential type. |
gatewayId | string | no | Select a gateway for private cluster access. If not specified, the Internet Gateway will be used. |
staticConfig | DynamicSecretKubernetesConfigurationStaticConfig (output) | no | Configuration for the 'static' credential type. |
DynamicSecretKubernetesConfigurationApiConfig (output)#
Output object DynamicSecretKubernetesConfigurationApiConfig. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
ca | string | no | Custom CA certificate for the Kubernetes API server. Leave blank to use the system/public CA. |
clusterToken | string | yes | Service account token with permissions to create service accounts and manage RBAC. |
clusterUrl | string | yes | Kubernetes API server URL (e.g., https://kubernetes.default.svc). |
enableSsl | boolean | no | Whether to enable SSL verification for the Kubernetes API server connection. |
DynamicSecretKubernetesConfigurationDynamicConfig (output)#
Output object DynamicSecretKubernetesConfigurationDynamicConfig. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
allowedNamespaces | string | yes | Kubernetes namespace(s) where the service accounts will be created. You can specify multiple namespaces as a comma-separated list (e.g., “default,kube-system”). During lease creation, you can specify which namespace to use from this allowed list. |
role | string | yes | Name of the role to assign to the temporary service account. |
roleType | string | yes | Type of role to assign ('cluster-role' or 'role'). |
DynamicSecretKubernetesConfigurationStaticConfig (output)#
Output object DynamicSecretKubernetesConfigurationStaticConfig. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
namespace | string | yes | Kubernetes namespace where the service account exists. |
serviceAccountName | string | yes | Name of the service account to generate tokens for. |
DynamicSecretKubernetesMetadata (output)#
Output object DynamicSecretKubernetesMetadata. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
key | string | yes | The key of the metadata object |
value | string | yes | The value of the metadata object |