# DynamicSecretKubernetes

> Resource DynamicSecretKubernetes in pulumi-infisical.

<!-- Generated from the pulumi-infisical SDK. -->

Resource DynamicSecretKubernetes in pulumi-infisical.

Pulumi type: `infisical:index/dynamicSecretKubernetes:DynamicSecretKubernetes`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as infisical from "pulumi-infisical"

const resource = new infisical.DynamicSecretKubernetes(
  "dynamicSecretKubernetes",
  {
    configuration: {
      authMethod: "<authMethod>",
      credentialType: "<credentialType>",
    },
    defaultTtl: "<defaultTtl>",
    environmentSlug: "<environmentSlug>",
    path: "<path>",
    projectSlug: "<projectSlug>",
  },
)
```

## Arguments

| Property           | Type                                           | Required | Description                                                  |
| ------------------ | ---------------------------------------------- | -------- | ------------------------------------------------------------ |
| `configuration`    | `DynamicSecretKubernetesConfiguration (input)` | yes      | The configuration of the dynamic secret                      |
| `defaultTtl`       | `string`                                       | yes      | The default TTL that will be applied for all the leases.     |
| `environmentSlug`  | `string`                                       | yes      | The slug of the environment to create the dynamic secret in. |
| `maxTtl`           | `string`                                       | no       | The maximum limit a TTL can be leased or renewed for.        |
| `metadatas`        | `DynamicSecretKubernetesMetadata (input)[]`    | no       | The metadata associated with this dynamic secret             |
| `name`             | `string`                                       | no       | The name of the dynamic secret.                              |
| `path`             | `string`                                       | yes      | The path to create the dynamic secret in.                    |
| `projectSlug`      | `string`                                       | yes      | The slug of the project to create dynamic secret in.         |
| `usernameTemplate` | `string`                                       | no       | The username template of the dynamic secret                  |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property           | Type                                            | Computed | Description                                                  |
| ------------------ | ----------------------------------------------- | -------- | ------------------------------------------------------------ |
| `configuration`    | `DynamicSecretKubernetesConfiguration (output)` | no       | The configuration of the dynamic secret                      |
| `defaultTtl`       | `string`                                        | no       | The default TTL that will be applied for all the leases.     |
| `environmentSlug`  | `string`                                        | no       | The slug of the environment to create the dynamic secret in. |
| `maxTtl`           | `string`                                        | no       | The maximum limit a TTL can be leased or renewed for.        |
| `metadatas`        | `DynamicSecretKubernetesMetadata (output)[]`    | no       | The metadata associated with this dynamic secret             |
| `name`             | `string`                                        | no       | The name of the dynamic secret.                              |
| `path`             | `string`                                        | no       | The path to create the dynamic secret in.                    |
| `projectSlug`      | `string`                                        | no       | The slug of the project to create dynamic secret in.         |
| `usernameTemplate` | `string`                                        | no       | The username template of the dynamic secret                  |

## `DynamicSecretKubernetesConfiguration (input)`

Input object `DynamicSecretKubernetesConfiguration`. Fields below belong to this object, not to the parent.

| Property         | Type                                                        | Required | Description                                                                                                                          |
| ---------------- | ----------------------------------------------------------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| `apiConfig`      | `DynamicSecretKubernetesConfigurationApiConfig (input)`     | no       | Configuration for the 'api' authentication method.                                                                                   |
| `audiences`      | `string[]`                                                  | no       | Optional list of audiences to include in the generated token.                                                                        |
| `authMethod`     | `string`                                                    | yes      | Choose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster. |
| `credentialType` | `string`                                                    | yes      | Choose between 'static' (predefined service account) or 'dynamic' (temporary service accounts with role assignments).                |
| `dynamicConfig`  | `DynamicSecretKubernetesConfigurationDynamicConfig (input)` | no       | Configuration for the 'dynamic' credential type.                                                                                     |
| `gatewayId`      | `string`                                                    | no       | Select a gateway for private cluster access. If not specified, the Internet Gateway will be used.                                    |
| `staticConfig`   | `DynamicSecretKubernetesConfigurationStaticConfig (input)`  | no       | Configuration for the 'static' credential type.                                                                                      |

## `DynamicSecretKubernetesConfigurationApiConfig (input)`

Input object `DynamicSecretKubernetesConfigurationApiConfig`. Fields below belong to this object, not to the parent.

| Property       | Type      | Required | Description                                                                                   |
| -------------- | --------- | -------- | --------------------------------------------------------------------------------------------- |
| `ca`           | `string`  | no       | Custom CA certificate for the Kubernetes API server. Leave blank to use the system/public CA. |
| `clusterToken` | `string`  | yes      | Service account token with permissions to create service accounts and manage RBAC.            |
| `clusterUrl`   | `string`  | yes      | Kubernetes API server URL (e.g., https://kubernetes.default.svc).                             |
| `enableSsl`    | `boolean` | no       | Whether to enable SSL verification for the Kubernetes API server connection.                  |

## `DynamicSecretKubernetesConfigurationDynamicConfig (input)`

Input object `DynamicSecretKubernetesConfigurationDynamicConfig`. Fields below belong to this object, not to the parent.

| Property            | Type     | Required | Description                                                                                                                                                                                                                                            |
| ------------------- | -------- | -------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `allowedNamespaces` | `string` | yes      | Kubernetes namespace(s) where the service accounts will be created. You can specify multiple namespaces as a comma-separated list (e.g., “default,kube-system”). During lease creation, you can specify which namespace to use from this allowed list. |
| `role`              | `string` | yes      | Name of the role to assign to the temporary service account.                                                                                                                                                                                           |
| `roleType`          | `string` | yes      | Type of role to assign ('cluster-role' or 'role').                                                                                                                                                                                                     |

## `DynamicSecretKubernetesConfigurationStaticConfig (input)`

Input object `DynamicSecretKubernetesConfigurationStaticConfig`. Fields below belong to this object, not to the parent.

| Property             | Type     | Required | Description                                            |
| -------------------- | -------- | -------- | ------------------------------------------------------ |
| `namespace`          | `string` | yes      | Kubernetes namespace where the service account exists. |
| `serviceAccountName` | `string` | yes      | Name of the service account to generate tokens for.    |

## `DynamicSecretKubernetesMetadata (input)`

Input object `DynamicSecretKubernetesMetadata`. Fields below belong to this object, not to the parent.

| Property | Type     | Required | Description                      |
| -------- | -------- | -------- | -------------------------------- |
| `key`    | `string` | yes      | The key of the metadata object   |
| `value`  | `string` | yes      | The value of the metadata object |

## `DynamicSecretKubernetesConfiguration (output)`

Output object `DynamicSecretKubernetesConfiguration`. Fields below belong to this object.

| Property         | Type                                                         | Always present | Description                                                                                                                          |
| ---------------- | ------------------------------------------------------------ | -------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| `apiConfig`      | `DynamicSecretKubernetesConfigurationApiConfig (output)`     | no             | Configuration for the 'api' authentication method.                                                                                   |
| `audiences`      | `string[]`                                                   | no             | Optional list of audiences to include in the generated token.                                                                        |
| `authMethod`     | `string`                                                     | yes            | Choose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster. |
| `credentialType` | `string`                                                     | yes            | Choose between 'static' (predefined service account) or 'dynamic' (temporary service accounts with role assignments).                |
| `dynamicConfig`  | `DynamicSecretKubernetesConfigurationDynamicConfig (output)` | no             | Configuration for the 'dynamic' credential type.                                                                                     |
| `gatewayId`      | `string`                                                     | no             | Select a gateway for private cluster access. If not specified, the Internet Gateway will be used.                                    |
| `staticConfig`   | `DynamicSecretKubernetesConfigurationStaticConfig (output)`  | no             | Configuration for the 'static' credential type.                                                                                      |

## `DynamicSecretKubernetesConfigurationApiConfig (output)`

Output object `DynamicSecretKubernetesConfigurationApiConfig`. Fields below belong to this object.

| Property       | Type      | Always present | Description                                                                                   |
| -------------- | --------- | -------------- | --------------------------------------------------------------------------------------------- |
| `ca`           | `string`  | no             | Custom CA certificate for the Kubernetes API server. Leave blank to use the system/public CA. |
| `clusterToken` | `string`  | yes            | Service account token with permissions to create service accounts and manage RBAC.            |
| `clusterUrl`   | `string`  | yes            | Kubernetes API server URL (e.g., https://kubernetes.default.svc).                             |
| `enableSsl`    | `boolean` | no             | Whether to enable SSL verification for the Kubernetes API server connection.                  |

## `DynamicSecretKubernetesConfigurationDynamicConfig (output)`

Output object `DynamicSecretKubernetesConfigurationDynamicConfig`. Fields below belong to this object.

| Property            | Type     | Always present | Description                                                                                                                                                                                                                                            |
| ------------------- | -------- | -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `allowedNamespaces` | `string` | yes            | Kubernetes namespace(s) where the service accounts will be created. You can specify multiple namespaces as a comma-separated list (e.g., “default,kube-system”). During lease creation, you can specify which namespace to use from this allowed list. |
| `role`              | `string` | yes            | Name of the role to assign to the temporary service account.                                                                                                                                                                                           |
| `roleType`          | `string` | yes            | Type of role to assign ('cluster-role' or 'role').                                                                                                                                                                                                     |

## `DynamicSecretKubernetesConfigurationStaticConfig (output)`

Output object `DynamicSecretKubernetesConfigurationStaticConfig`. Fields below belong to this object.

| Property             | Type     | Always present | Description                                            |
| -------------------- | -------- | -------------- | ------------------------------------------------------ |
| `namespace`          | `string` | yes            | Kubernetes namespace where the service account exists. |
| `serviceAccountName` | `string` | yes            | Name of the service account to generate tokens for.    |

## `DynamicSecretKubernetesMetadata (output)`

Output object `DynamicSecretKubernetesMetadata`. Fields below belong to this object.

| Property | Type     | Always present | Description                      |
| -------- | -------- | -------------- | -------------------------------- |
| `key`    | `string` | yes            | The key of the metadata object   |
| `value`  | `string` | yes            | The value of the metadata object |
