Skip to main content

Gateway

Resource Gateway in pulumi-infisical.
8 min read

Resource Gateway in pulumi-infisical.

Pulumi type: infisical:index/gateway:Gateway.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
awsAuthGatewayAwsAuth (input)noAuthenticate the gateway with its AWS IAM identity. The machine re-authenticates on every start, so no secret is stored. At least one of allowedPrincipalArns or allowedAccountIds must be non-empty.
gcpAuthGatewayGcpAuth (input)noAuthenticate the gateway with its GCP identity. The machine re-authenticates on every start, so no secret is stored. At least one of allowedServiceAccounts or allowedProjects must be non-empty.
kubernetesAuthGatewayKubernetesAuth (input)noAuthenticate the gateway with its Kubernetes service account token. The pod re-authenticates on every start, so no secret is stored. At least one of allowedNamespaces or allowedServiceAccountNames must be non-empty.
namestringnoThe name of the gateway. Unique within the organization. Renaming is an in-place update, so the gateway keeps its ID and anything referencing it keeps working.
tokenAuthGatewayTokenAuth (input)noAuthenticate the gateway with a one-time enrollment token. The token itself is minted by a separate 'infisical.GatewayEnrollmentToken' resource. This block takes no arguments, because token auth has nothing to configure: write 'tokenAuth'= {}'. Prefer 'awsAuth', 'gcpAuth' or 'kubernetesAuth' where the platform can vouch for the machine, since those re-authenticate on every start and put no secret in state.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
awsAuthGatewayAwsAuth (output)noAuthenticate the gateway with its AWS IAM identity. The machine re-authenticates on every start, so no secret is stored. At least one of allowedPrincipalArns or allowedAccountIds must be non-empty.
gcpAuthGatewayGcpAuth (output)noAuthenticate the gateway with its GCP identity. The machine re-authenticates on every start, so no secret is stored. At least one of allowedServiceAccounts or allowedProjects must be non-empty.
kubernetesAuthGatewayKubernetesAuth (output)noAuthenticate the gateway with its Kubernetes service account token. The pod re-authenticates on every start, so no secret is stored. At least one of allowedNamespaces or allowedServiceAccountNames must be non-empty.
namestringnoThe name of the gateway. Unique within the organization. Renaming is an in-place update, so the gateway keeps its ID and anything referencing it keeps working.
tokenAuthGatewayTokenAuth (output)noAuthenticate the gateway with a one-time enrollment token. The token itself is minted by a separate 'infisical.GatewayEnrollmentToken' resource. This block takes no arguments, because token auth has nothing to configure: write 'tokenAuth'= {}'. Prefer 'awsAuth', 'gcpAuth' or 'kubernetesAuth' where the platform can vouch for the machine, since those re-authenticate on every start and put no secret in state.

GatewayAwsAuth (input)#

Input object GatewayAwsAuth. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedAccountIdsstring[]noAWS account IDs allowed to authenticate as this gateway.
allowedPrincipalArnsstring[]noIAM principal ARNs allowed to authenticate as this gateway. Supports * wildcards.

GatewayGcpAuth (input)#

Input object GatewayGcpAuth. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedProjectsstring[]noGCP project IDs whose Compute Engine instances are allowed to authenticate as this gateway. Only applies when type is gce.
allowedServiceAccountsstring[]noGCP service account emails allowed to authenticate as this gateway.
allowedZonesstring[]noGCP zones whose Compute Engine instances are allowed to authenticate as this gateway. Only applies when type is gce.
typestringnoHow the gateway proves its identity. gce verifies an ID token from the instance metadata server, which covers Compute Engine VMs and GKE workload identity. iam verifies a JWT the service account signed through the IAM Credentials API, for hosts outside Compute Engine. Defaults to gce.

GatewayKubernetesAuth (input)#

Input object GatewayKubernetesAuth. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
allowedAudiencestringnoThe audience the service account token must carry. Leave empty to skip the audience check.
allowedNamespacesstring[]noKubernetes namespaces whose service accounts are allowed to authenticate as this gateway. Supports * wildcards.
allowedServiceAccountNamesstring[]noKubernetes service account names allowed to authenticate as this gateway. Supports * wildcards.
caCertificatestringnoThe PEM-encoded CA certificate that issued the Kubernetes API server's TLS certificate.
hasTokenReviewerJwtbooleannoWhether Infisical holds a token reviewer JWT for this gateway. The JWT itself is never returned, so this is the only way to tell a stored one apart from none.
kubernetesHoststringnoThe URL of the Kubernetes API server, for example https://my-cluster.example.com:6443. Must be https with no path, and reachable from Infisical over the public internet. Required unless tokenReviewMode is gateway, where it must be omitted.
reviewerGatewayIdstringnoThe gateway that performs the TokenReview. Required when tokenReviewMode is gateway, and must be a different gateway that is already connected in the cluster. Mutually exclusive with reviewerGatewayPoolId.
reviewerGatewayPoolIdstringnoThe gateway pool to route TokenReview traffic through. Mutually exclusive with reviewerGatewayId, and rejected when tokenReviewMode is gateway.
tokenReviewModestringnoWho performs the TokenReview. api means Infisical does, calling kubernetesHost directly. gateway means another already-connected gateway does it with its own in-cluster service account, which needs no host or reviewer token. Defaults to api.
tokenReviewerJwtstringnoA long-lived service account token with the system:auth-delegator ClusterRole, used to submit TokenReview requests. Write-only: Infisical never returns it, so Terraform cannot detect a change made outside this configuration, and an imported gateway leaves it empty.
verifyTlsCertificatebooleannoWhether to verify the Kubernetes API server's TLS certificate. Defaults to true.

GatewayTokenAuth (input)#

Input object GatewayTokenAuth. Fields below belong to this object, not to the parent.

This object has no fields.

GatewayAwsAuth (output)#

Output object GatewayAwsAuth. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedAccountIdsstring[]noAWS account IDs allowed to authenticate as this gateway.
allowedPrincipalArnsstring[]noIAM principal ARNs allowed to authenticate as this gateway. Supports * wildcards.

GatewayGcpAuth (output)#

Output object GatewayGcpAuth. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedProjectsstring[]noGCP project IDs whose Compute Engine instances are allowed to authenticate as this gateway. Only applies when type is gce.
allowedServiceAccountsstring[]noGCP service account emails allowed to authenticate as this gateway.
allowedZonesstring[]noGCP zones whose Compute Engine instances are allowed to authenticate as this gateway. Only applies when type is gce.
typestringyesHow the gateway proves its identity. gce verifies an ID token from the instance metadata server, which covers Compute Engine VMs and GKE workload identity. iam verifies a JWT the service account signed through the IAM Credentials API, for hosts outside Compute Engine. Defaults to gce.

GatewayKubernetesAuth (output)#

Output object GatewayKubernetesAuth. Fields below belong to this object.

PropertyTypeAlways presentDescription
allowedAudiencestringnoThe audience the service account token must carry. Leave empty to skip the audience check.
allowedNamespacesstring[]noKubernetes namespaces whose service accounts are allowed to authenticate as this gateway. Supports * wildcards.
allowedServiceAccountNamesstring[]noKubernetes service account names allowed to authenticate as this gateway. Supports * wildcards.
caCertificatestringnoThe PEM-encoded CA certificate that issued the Kubernetes API server's TLS certificate.
hasTokenReviewerJwtbooleanyesWhether Infisical holds a token reviewer JWT for this gateway. The JWT itself is never returned, so this is the only way to tell a stored one apart from none.
kubernetesHoststringyesThe URL of the Kubernetes API server, for example https://my-cluster.example.com:6443. Must be https with no path, and reachable from Infisical over the public internet. Required unless tokenReviewMode is gateway, where it must be omitted.
reviewerGatewayIdstringnoThe gateway that performs the TokenReview. Required when tokenReviewMode is gateway, and must be a different gateway that is already connected in the cluster. Mutually exclusive with reviewerGatewayPoolId.
reviewerGatewayPoolIdstringnoThe gateway pool to route TokenReview traffic through. Mutually exclusive with reviewerGatewayId, and rejected when tokenReviewMode is gateway.
tokenReviewModestringyesWho performs the TokenReview. api means Infisical does, calling kubernetesHost directly. gateway means another already-connected gateway does it with its own in-cluster service account, which needs no host or reviewer token. Defaults to api.
tokenReviewerJwtstringnoA long-lived service account token with the system:auth-delegator ClusterRole, used to submit TokenReview requests. Write-only: Infisical never returns it, so Terraform cannot detect a change made outside this configuration, and an imported gateway leaves it empty.
verifyTlsCertificatebooleanyesWhether to verify the Kubernetes API server's TLS certificate. Defaults to true.

GatewayTokenAuth (output)#

Output object GatewayTokenAuth. Fields below belong to this object.

This object has no fields.