Skip to main content

DynamicSecretKubernetes

Resource DynamicSecretKubernetes in pulumi-infisical.
7 min read

Resource DynamicSecretKubernetes in pulumi-infisical.

Pulumi type: infisical:index/dynamicSecretKubernetes:DynamicSecretKubernetes.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
configurationDynamicSecretKubernetesConfiguration (input)yesThe configuration of the dynamic secret
defaultTtlstringyesThe default TTL that will be applied for all the leases.
environmentSlugstringyesThe slug of the environment to create the dynamic secret in.
maxTtlstringnoThe maximum limit a TTL can be leased or renewed for.
metadatasDynamicSecretKubernetesMetadata (input)[]noThe metadata associated with this dynamic secret
namestringnoThe name of the dynamic secret.
pathstringyesThe path to create the dynamic secret in.
projectSlugstringyesThe slug of the project to create dynamic secret in.
usernameTemplatestringnoThe username template of the dynamic secret

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
configurationDynamicSecretKubernetesConfiguration (output)noThe configuration of the dynamic secret
defaultTtlstringnoThe default TTL that will be applied for all the leases.
environmentSlugstringnoThe slug of the environment to create the dynamic secret in.
maxTtlstringnoThe maximum limit a TTL can be leased or renewed for.
metadatasDynamicSecretKubernetesMetadata (output)[]noThe metadata associated with this dynamic secret
namestringnoThe name of the dynamic secret.
pathstringnoThe path to create the dynamic secret in.
projectSlugstringnoThe slug of the project to create dynamic secret in.
usernameTemplatestringnoThe username template of the dynamic secret

DynamicSecretKubernetesConfiguration (input)#

Input object DynamicSecretKubernetesConfiguration. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
apiConfigDynamicSecretKubernetesConfigurationApiConfig (input)noConfiguration for the 'api' authentication method.
audiencesstring[]noOptional list of audiences to include in the generated token.
authMethodstringyesChoose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster.
credentialTypestringyesChoose between 'static' (predefined service account) or 'dynamic' (temporary service accounts with role assignments).
dynamicConfigDynamicSecretKubernetesConfigurationDynamicConfig (input)noConfiguration for the 'dynamic' credential type.
gatewayIdstringnoSelect a gateway for private cluster access. If not specified, the Internet Gateway will be used.
staticConfigDynamicSecretKubernetesConfigurationStaticConfig (input)noConfiguration for the 'static' credential type.

DynamicSecretKubernetesConfigurationApiConfig (input)#

Input object DynamicSecretKubernetesConfigurationApiConfig. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
castringnoCustom CA certificate for the Kubernetes API server. Leave blank to use the system/public CA.
clusterTokenstringyesService account token with permissions to create service accounts and manage RBAC.
clusterUrlstringyesKubernetes API server URL (e.g., https://kubernetes.default.svc).
enableSslbooleannoWhether to enable SSL verification for the Kubernetes API server connection.

DynamicSecretKubernetesConfigurationDynamicConfig (input)#

Input object DynamicSecretKubernetesConfigurationDynamicConfig. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedNamespacesstringyesKubernetes namespace(s) where the service accounts will be created. You can specify multiple namespaces as a comma-separated list (e.g., “default,kube-system”). During lease creation, you can specify which namespace to use from this allowed list.
rolestringyesName of the role to assign to the temporary service account.
roleTypestringyesType of role to assign ('cluster-role' or 'role').

DynamicSecretKubernetesConfigurationStaticConfig (input)#

Input object DynamicSecretKubernetesConfigurationStaticConfig. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
namespacestringyesKubernetes namespace where the service account exists.
serviceAccountNamestringyesName of the service account to generate tokens for.

DynamicSecretKubernetesMetadata (input)#

Input object DynamicSecretKubernetesMetadata. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
keystringyesThe key of the metadata object
valuestringyesThe value of the metadata object

DynamicSecretKubernetesConfiguration (output)#

Output object DynamicSecretKubernetesConfiguration. Fields below belong to this object.

PropertyTypeAlways presentDescription
apiConfigDynamicSecretKubernetesConfigurationApiConfig (output)noConfiguration for the 'api' authentication method.
audiencesstring[]noOptional list of audiences to include in the generated token.
authMethodstringyesChoose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster.
credentialTypestringyesChoose between 'static' (predefined service account) or 'dynamic' (temporary service accounts with role assignments).
dynamicConfigDynamicSecretKubernetesConfigurationDynamicConfig (output)noConfiguration for the 'dynamic' credential type.
gatewayIdstringnoSelect a gateway for private cluster access. If not specified, the Internet Gateway will be used.
staticConfigDynamicSecretKubernetesConfigurationStaticConfig (output)noConfiguration for the 'static' credential type.

DynamicSecretKubernetesConfigurationApiConfig (output)#

Output object DynamicSecretKubernetesConfigurationApiConfig. Fields below belong to this object.

PropertyTypeAlways presentDescription
castringnoCustom CA certificate for the Kubernetes API server. Leave blank to use the system/public CA.
clusterTokenstringyesService account token with permissions to create service accounts and manage RBAC.
clusterUrlstringyesKubernetes API server URL (e.g., https://kubernetes.default.svc).
enableSslbooleannoWhether to enable SSL verification for the Kubernetes API server connection.

DynamicSecretKubernetesConfigurationDynamicConfig (output)#

Output object DynamicSecretKubernetesConfigurationDynamicConfig. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedNamespacesstringyesKubernetes namespace(s) where the service accounts will be created. You can specify multiple namespaces as a comma-separated list (e.g., “default,kube-system”). During lease creation, you can specify which namespace to use from this allowed list.
rolestringyesName of the role to assign to the temporary service account.
roleTypestringyesType of role to assign ('cluster-role' or 'role').

DynamicSecretKubernetesConfigurationStaticConfig (output)#

Output object DynamicSecretKubernetesConfigurationStaticConfig. Fields below belong to this object.

PropertyTypeAlways presentDescription
namespacestringyesKubernetes namespace where the service account exists.
serviceAccountNamestringyesName of the service account to generate tokens for.

DynamicSecretKubernetesMetadata (output)#

Output object DynamicSecretKubernetesMetadata. Fields below belong to this object.

PropertyTypeAlways presentDescription
keystringyesThe key of the metadata object
valuestringyesThe value of the metadata object