Resource IdentityTlsCertAuth in pulumi-infisical.
Pulumi type: infisical:index/identityTlsCertAuth:IdentityTlsCertAuth.
name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.
Example#
Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.
Arguments#
| Property | Type | Required | Description |
|---|---|---|---|
accessTokenMaxTtl | number | no | The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 |
accessTokenNumUsesLimit | number | no | The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0 |
accessTokenTrustedIps | IdentityTlsCertAuthAccessTokenTrustedIp (input)[] | no | A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address.. |
accessTokenTtl | number | no | The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 |
allowedCommonNames | string[] | no | List of trusted common names that client certificates must have to authenticate with Infisical. When omitted, any common name is accepted. |
allowedSubjectAltNames | string[] | no | List of trusted subject alternative names that client certificates must have to authenticate with Infisical. Non-DNS entries must be prefixed with their type (e.g. URI:spiffe://example.org/service, IP:10.0.0.1, EMAIL:svc@example.com). When omitted, any subject alternative name is accepted. |
caCertificate | string | yes | The PEM-encoded CA certificate that client certificates must be issued by to authenticate with Infisical. |
identityId | string | yes | The ID of the identity to attach the configuration onto. |
verifyClientCertificateChain | boolean | no | Whether to build and verify the full certificate chain presented by the client up to the configured CA certificate, instead of requiring the client certificate to be signed directly by it. Default: false |
Outputs#
Computed outputs are produced by the provider. They are not constructor arguments.
| Property | Type | Computed | Description |
|---|---|---|---|
accessTokenMaxTtl | number | no | The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 |
accessTokenNumUsesLimit | number | no | The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0 |
accessTokenTrustedIps | IdentityTlsCertAuthAccessTokenTrustedIp (output)[] | no | A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address.. |
accessTokenTtl | number | no | The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 |
allowedCommonNames | string[] | no | List of trusted common names that client certificates must have to authenticate with Infisical. When omitted, any common name is accepted. |
allowedSubjectAltNames | string[] | no | List of trusted subject alternative names that client certificates must have to authenticate with Infisical. Non-DNS entries must be prefixed with their type (e.g. URI:spiffe://example.org/service, IP:10.0.0.1, EMAIL:svc@example.com). When omitted, any subject alternative name is accepted. |
caCertificate | string | no | The PEM-encoded CA certificate that client certificates must be issued by to authenticate with Infisical. |
identityId | string | no | The ID of the identity to attach the configuration onto. |
verifyClientCertificateChain | boolean | no | Whether to build and verify the full certificate chain presented by the client up to the configured CA certificate, instead of requiring the client certificate to be signed directly by it. Default: false |
IdentityTlsCertAuthAccessTokenTrustedIp (input)#
Input object IdentityTlsCertAuthAccessTokenTrustedIp. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
ipAddress | string | no |
IdentityTlsCertAuthAccessTokenTrustedIp (output)#
Output object IdentityTlsCertAuthAccessTokenTrustedIp. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
ipAddress | string | yes |