Skip to main content

IdentityGcpAuth

Resource IdentityGcpAuth in pulumi-infisical.
4 min read

Resource IdentityGcpAuth in pulumi-infisical.

Pulumi type: infisical:index/identityGcpAuth:IdentityGcpAuth.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
accessTokenMaxTtlnumbernoThe maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
accessTokenNumUsesLimitnumbernoThe maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0
accessTokenTrustedIpsIdentityGcpAuthAccessTokenTrustedIp (input)[]noA list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address..
accessTokenTtlnumbernoThe lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
allowedProjectsstring[]noList of trusted GCP projects that the GCE instance must belong to authenticate with Infisical. Note that this validation property will only work for GCE instances
allowedServiceAccountEmailsstring[]noList of trusted service account emails corresponding to the GCE resource(s) allowed to authenticate with Infisical; this could be something like test@project.iam.gserviceaccount.com, 12345-compute@developer.gserviceaccount.com, etc.
allowedZonesstring[]noList of trusted zones that the GCE instances must belong to authenticate with Infisical; this should be the fully-qualified zone name in the format <region>-<zone>like us-central1-a, us-west1-b, etc. Note that this validation property will only work for GCE instances.
identityIdstringyesThe ID of the identity to attach the configuration onto.
typestringnoThe Type of GCP Auth Method to use: Options are gce, iam. Default:gce

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
accessTokenMaxTtlnumbernoThe maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
accessTokenNumUsesLimitnumbernoThe maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0
accessTokenTrustedIpsIdentityGcpAuthAccessTokenTrustedIp (output)[]noA list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address..
accessTokenTtlnumbernoThe lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
allowedProjectsstring[]noList of trusted GCP projects that the GCE instance must belong to authenticate with Infisical. Note that this validation property will only work for GCE instances
allowedServiceAccountEmailsstring[]noList of trusted service account emails corresponding to the GCE resource(s) allowed to authenticate with Infisical; this could be something like test@project.iam.gserviceaccount.com, 12345-compute@developer.gserviceaccount.com, etc.
allowedZonesstring[]noList of trusted zones that the GCE instances must belong to authenticate with Infisical; this should be the fully-qualified zone name in the format <region>-<zone>like us-central1-a, us-west1-b, etc. Note that this validation property will only work for GCE instances.
identityIdstringnoThe ID of the identity to attach the configuration onto.
typestringnoThe Type of GCP Auth Method to use: Options are gce, iam. Default:gce

IdentityGcpAuthAccessTokenTrustedIp (input)#

Input object IdentityGcpAuthAccessTokenTrustedIp. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
ipAddressstringno

IdentityGcpAuthAccessTokenTrustedIp (output)#

Output object IdentityGcpAuthAccessTokenTrustedIp. Fields below belong to this object.

PropertyTypeAlways presentDescription
ipAddressstringyes