Skip to main content

ExternalKmsAws

Resource ExternalKmsAws in pulumi-infisical.
4 min read

Resource ExternalKmsAws in pulumi-infisical.

Pulumi type: infisical:index/externalKmsAws:ExternalKmsAws.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
configurationExternalKmsAwsConfiguration (input)yesThe configuration for the AWS External KMS
descriptionstringnoAn optional description for the KMS.
namestringnoThe name of the KMS to create. Must be slug-friendly

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
configurationExternalKmsAwsConfiguration (output)noThe configuration for the AWS External KMS
credentialsHashstringyesThe hash of the AWS External KMS credentials
descriptionstringnoAn optional description for the KMS.
namestringnoThe name of the KMS to create. Must be slug-friendly

ExternalKmsAwsConfiguration (input)#

Input object ExternalKmsAwsConfiguration. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
awsKmsKeyIdstringyesThe AWS KMS key ID to use for the external KMS. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-aws-kms-key-id
awsRegionstringyesThe AWS region where the KMS key is located
credentialExternalKmsAwsConfigurationCredential (input)yesThe AWS credentials for the external KMS
typestringyesThe Authentication Type to use. Must be access-key or assume-role

ExternalKmsAwsConfigurationCredential (input)#

Input object ExternalKmsAwsConfigurationCredential. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
accessKeyIdstringnoThe AWS Access Key ID used to authenticate requests to AWS services. Required for access-key type. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-access-key-id
roleArnstringnoThe Amazon Resource Name (ARN) of the IAM role to assume for performing operations. Infisical will assume this role using AWS Security Token Service (STS). Required for assume-role type. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-iam-role-arn-for-role-assumption
roleExternalIdstringnoThe external ID of the role to assume for performing operations. Required for assume-role type. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-assume-role-external-id
secretAccessKeystringnoThe AWS Secret Access Key associated with the Access Key ID to authenticate requests to AWS services. Required for access-key type. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-secret-access-key

ExternalKmsAwsConfiguration (output)#

Output object ExternalKmsAwsConfiguration. Fields below belong to this object.

PropertyTypeAlways presentDescription
awsKmsKeyIdstringyesThe AWS KMS key ID to use for the external KMS. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-aws-kms-key-id
awsRegionstringyesThe AWS region where the KMS key is located
credentialExternalKmsAwsConfigurationCredential (output)yesThe AWS credentials for the external KMS
typestringyesThe Authentication Type to use. Must be access-key or assume-role

ExternalKmsAwsConfigurationCredential (output)#

Output object ExternalKmsAwsConfigurationCredential. Fields below belong to this object.

PropertyTypeAlways presentDescription
accessKeyIdstringnoThe AWS Access Key ID used to authenticate requests to AWS services. Required for access-key type. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-access-key-id
roleArnstringnoThe Amazon Resource Name (ARN) of the IAM role to assume for performing operations. Infisical will assume this role using AWS Security Token Service (STS). Required for assume-role type. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-iam-role-arn-for-role-assumption
roleExternalIdstringnoThe external ID of the role to assume for performing operations. Required for assume-role type. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-assume-role-external-id
secretAccessKeystringnoThe AWS Secret Access Key associated with the Access Key ID to authenticate requests to AWS services. Required for access-key type. For more details, refer to the documentation here https://infisical.com/docs/documentation/platform/kms-configuration/aws-kms#param-secret-access-key