Resource IdentityOidcAuth in pulumi-infisical.
Pulumi type: infisical:index/identityOidcAuth:IdentityOidcAuth.
name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.
Example#
Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.
Arguments#
| Property | Type | Required | Description |
|---|---|---|---|
accessTokenMaxTtl | number | no | The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 |
accessTokenNumUsesLimit | number | no | The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0 |
accessTokenTrustedIps | IdentityOidcAuthAccessTokenTrustedIp (input)[] | no | A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address... |
accessTokenTtl | number | no | The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 |
boundAudiences | string[] | no | The comma-separated list of intended recipients. |
boundClaims | { [key: string]: string } | no | The attributes that should be present in the JWT for it to be valid. The provided values can be a glob pattern. |
boundIssuer | string | yes | The unique identifier of the identity provider issuing the OIDC tokens. |
boundSubject | string | no | The expected principal that is the subject of the JWT. |
claimMetadataMapping | { [key: string]: string } | no | Map OIDC token claims to metadata fields. Example: {"role": "token.groups"}, this would become identity.metadata.oidc.claims.role |
identityId | string | yes | The ID of the identity to attach the configuration onto. |
oidcCaCertificate | string | no | The PEM-encoded CA cert for establishing secure communication with the Identity Provider endpoints |
oidcDiscoveryUrl | string | yes | The URL used to retrieve the OpenID Connect configuration from the identity provider. |
Outputs#
Computed outputs are produced by the provider. They are not constructor arguments.
| Property | Type | Computed | Description |
|---|---|---|---|
accessTokenMaxTtl | number | no | The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 |
accessTokenNumUsesLimit | number | no | The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0 |
accessTokenTrustedIps | IdentityOidcAuthAccessTokenTrustedIp (output)[] | no | A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address... |
accessTokenTtl | number | no | The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 |
boundAudiences | string[] | no | The comma-separated list of intended recipients. |
boundClaims | { [key: string]: string } | no | The attributes that should be present in the JWT for it to be valid. The provided values can be a glob pattern. |
boundIssuer | string | no | The unique identifier of the identity provider issuing the OIDC tokens. |
boundSubject | string | no | The expected principal that is the subject of the JWT. |
claimMetadataMapping | { [key: string]: string } | no | Map OIDC token claims to metadata fields. Example: {"role": "token.groups"}, this would become identity.metadata.oidc.claims.role |
identityId | string | no | The ID of the identity to attach the configuration onto. |
oidcCaCertificate | string | no | The PEM-encoded CA cert for establishing secure communication with the Identity Provider endpoints |
oidcDiscoveryUrl | string | no | The URL used to retrieve the OpenID Connect configuration from the identity provider. |
IdentityOidcAuthAccessTokenTrustedIp (input)#
Input object IdentityOidcAuthAccessTokenTrustedIp. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
ipAddress | string | no |
IdentityOidcAuthAccessTokenTrustedIp (output)#
Output object IdentityOidcAuthAccessTokenTrustedIp. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
ipAddress | string | yes |