Skip to main content

IdentityJwtAuth

Resource IdentityJwtAuth in pulumi-infisical.
4 min read

Resource IdentityJwtAuth in pulumi-infisical.

Pulumi type: infisical:index/identityJwtAuth:IdentityJwtAuth.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
accessTokenMaxTtlnumbernoThe maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
accessTokenNumUsesLimitnumbernoThe maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default: 0
accessTokenTrustedIpsIdentityJwtAuthAccessTokenTrustedIp (input)[]noA list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address.
accessTokenTtlnumbernoThe lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
boundAudiencesstring[]noThe list of intended recipients.
boundClaims{ [key: string]: string }noThe attributes that should be present in the JWT for it to be valid.
boundIssuerstringnoThe unique identifier of the identity provider issuing the JWTs.
boundSubjectstringnoThe expected principal that is the subject of the JWT.
configurationTypestringyesThe configuration type of the JWT auth. Must be 'jwks' or 'static'.
identityIdstringyesThe ID of the identity to attach the configuration onto.
jwksCaCertstringnoThe PEM-encoded CA certificate for validating the TLS connection to the JWKS URL.
jwksUrlstringnoThe URL used to retrieve the JSON Web Key Set (JWKS) for verifying JWTs. Required when configurationType is 'jwks'.
publicKeysstring[]noA list of PEM-encoded public keys used to verify JWTs. Required when configurationType is 'static'.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
accessTokenMaxTtlnumbernoThe maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
accessTokenNumUsesLimitnumbernoThe maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default: 0
accessTokenTrustedIpsIdentityJwtAuthAccessTokenTrustedIp (output)[]noA list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address.
accessTokenTtlnumbernoThe lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
boundAudiencesstring[]noThe list of intended recipients.
boundClaims{ [key: string]: string }noThe attributes that should be present in the JWT for it to be valid.
boundIssuerstringnoThe unique identifier of the identity provider issuing the JWTs.
boundSubjectstringnoThe expected principal that is the subject of the JWT.
configurationTypestringnoThe configuration type of the JWT auth. Must be 'jwks' or 'static'.
identityIdstringnoThe ID of the identity to attach the configuration onto.
jwksCaCertstringnoThe PEM-encoded CA certificate for validating the TLS connection to the JWKS URL.
jwksUrlstringnoThe URL used to retrieve the JSON Web Key Set (JWKS) for verifying JWTs. Required when configurationType is 'jwks'.
publicKeysstring[]noA list of PEM-encoded public keys used to verify JWTs. Required when configurationType is 'static'.

IdentityJwtAuthAccessTokenTrustedIp (input)#

Input object IdentityJwtAuthAccessTokenTrustedIp. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
ipAddressstringno

IdentityJwtAuthAccessTokenTrustedIp (output)#

Output object IdentityJwtAuthAccessTokenTrustedIp. Fields below belong to this object.

PropertyTypeAlways presentDescription
ipAddressstringyes