Skip to main content

IdentityKubernetesAuth

Resource IdentityKubernetesAuth in pulumi-infisical.
4 min read

Resource IdentityKubernetesAuth in pulumi-infisical.

Pulumi type: infisical:index/identityKubernetesAuth:IdentityKubernetesAuth.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
accessTokenMaxTtlnumbernoThe maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
accessTokenNumUsesLimitnumbernoThe maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0
accessTokenTrustedIpsIdentityKubernetesAuthAccessTokenTrustedIp (input)[]noA list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address..
accessTokenTtlnumbernoThe lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
allowedAudiencestringnoAn optional audience claim that the service account JWT token must have to authenticate with Infisical.
allowedNamespacesstring[]noList of trusted namespaces that service accounts must belong to authenticate with Infisical.
allowedServiceAccountNamesstring[]noList of trusted service account names that are allowed to authenticate with Infisical.
gatewayIdstringnoSelect a gateway for private cluster access. If not specified, the Internet Gateway will be used.
identityIdstringyesThe ID of the identity to attach the configuration onto.
kubernetesCaCertificatestringnoThe PEM-encoded CA cert for the Kubernetes API server. This is used by the TLS client for secure communication with the Kubernetes API server.
kubernetesHoststringnoThe host string, host:port pair, or URL to the base of the Kubernetes API server. This can usually be obtained by running kubectl cluster-info.
tokenReviewerJwtstringnoA long-lived service account JWT token for Infisical to access the TokenReview API to validate other service account JWT tokens submitted by applications/pods. This is the JWT token obtained from step 1.5.
tokenReviewerModestringnoChoose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
accessTokenMaxTtlnumbernoThe maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
accessTokenNumUsesLimitnumbernoThe maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0
accessTokenTrustedIpsIdentityKubernetesAuthAccessTokenTrustedIp (output)[]noA list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address..
accessTokenTtlnumbernoThe lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000
allowedAudiencestringnoAn optional audience claim that the service account JWT token must have to authenticate with Infisical.
allowedNamespacesstring[]noList of trusted namespaces that service accounts must belong to authenticate with Infisical.
allowedServiceAccountNamesstring[]noList of trusted service account names that are allowed to authenticate with Infisical.
gatewayIdstringnoSelect a gateway for private cluster access. If not specified, the Internet Gateway will be used.
identityIdstringnoThe ID of the identity to attach the configuration onto.
kubernetesCaCertificatestringnoThe PEM-encoded CA cert for the Kubernetes API server. This is used by the TLS client for secure communication with the Kubernetes API server.
kubernetesHoststringnoThe host string, host:port pair, or URL to the base of the Kubernetes API server. This can usually be obtained by running kubectl cluster-info.
tokenReviewerJwtstringnoA long-lived service account JWT token for Infisical to access the TokenReview API to validate other service account JWT tokens submitted by applications/pods. This is the JWT token obtained from step 1.5.
tokenReviewerModestringnoChoose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster.

IdentityKubernetesAuthAccessTokenTrustedIp (input)#

Input object IdentityKubernetesAuthAccessTokenTrustedIp. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
ipAddressstringno

IdentityKubernetesAuthAccessTokenTrustedIp (output)#

Output object IdentityKubernetesAuthAccessTokenTrustedIp. Fields below belong to this object.

PropertyTypeAlways presentDescription
ipAddressstringyes