Skip to main content

IdentityAwsAuth

Resource IdentityAwsAuth in pulumi-infisical.
3 min read

Resource IdentityAwsAuth in pulumi-infisical.

Pulumi type: infisical:index/identityAwsAuth:IdentityAwsAuth.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
accessTokenMaxTtlnumbernoThe maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
accessTokenNumUsesLimitnumbernoThe maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0
accessTokenTrustedIpsIdentityAwsAuthAccessTokenTrustedIp (input)[]noA list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address..
accessTokenTtlnumbernoThe lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
allowedAccountIdsstring[]noList of trusted AWS account IDs that are allowed to authenticate with Infisical.
allowedPrincipalArnsstring[]noList of trusted IAM principal ARNs that are allowed to authenticate with Infisical. The values should take one of three forms: arn:aws:iam::123456789012:user/MyUserName, arn:aws:iam::123456789012:role/MyRoleName, or arn:aws:iam::123456789012:*. Using a wildcard in this case allows any IAM principal in the account 123456789012 to authenticate with Infisical under the identity
identityIdstringyesThe ID of the identity to attach the configuration onto.
stsEndpointstringnoThe endpoint URL for the AWS STS API. This value should be adjusted based on the AWS region you are operating in (e.g. https://sts.us-east-1.amazonaws.com/); refer to the list of regional STS endpoints here.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
accessTokenMaxTtlnumbernoThe maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
accessTokenNumUsesLimitnumbernoThe maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0
accessTokenTrustedIpsIdentityAwsAuthAccessTokenTrustedIp (output)[]noA list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address..
accessTokenTtlnumbernoThe lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
allowedAccountIdsstring[]noList of trusted AWS account IDs that are allowed to authenticate with Infisical.
allowedPrincipalArnsstring[]noList of trusted IAM principal ARNs that are allowed to authenticate with Infisical. The values should take one of three forms: arn:aws:iam::123456789012:user/MyUserName, arn:aws:iam::123456789012:role/MyRoleName, or arn:aws:iam::123456789012:*. Using a wildcard in this case allows any IAM principal in the account 123456789012 to authenticate with Infisical under the identity
identityIdstringnoThe ID of the identity to attach the configuration onto.
stsEndpointstringnoThe endpoint URL for the AWS STS API. This value should be adjusted based on the AWS region you are operating in (e.g. https://sts.us-east-1.amazonaws.com/); refer to the list of regional STS endpoints here.

IdentityAwsAuthAccessTokenTrustedIp (input)#

Input object IdentityAwsAuthAccessTokenTrustedIp. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
ipAddressstringno

IdentityAwsAuthAccessTokenTrustedIp (output)#

Output object IdentityAwsAuthAccessTokenTrustedIp. Fields below belong to this object.

PropertyTypeAlways presentDescription
ipAddressstringyes