Skip to main content

ProjectIdentitySpecificPrivilege

Resource ProjectIdentitySpecificPrivilege in pulumi-infisical.
5 min read

Resource ProjectIdentitySpecificPrivilege in pulumi-infisical.

Pulumi type: infisical:index/projectIdentitySpecificPrivilege:ProjectIdentitySpecificPrivilege.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
identityIdstringyesThe identity id to create identity specific privilege
isTemporarybooleannoFlag to indicate the assigned specific privilege is temporary or not. When isTemporary is true fields temporary_mode,temporaryRange and temporaryAccessStartTime is required.
permissionProjectIdentitySpecificPrivilegePermission (input)no(DEPRECATED, USE permissions_v2. Refer to the migration guide in https://infisical.com/docs/internals/permissions#migrating-from-permission-v1-to-permission-v2) The permissions assigned to the project identity specific privilege
permissionsV2sProjectIdentitySpecificPrivilegePermissionsV2 (input)[]noThe permissions assigned to the project identity specific privilege. Refer to the documentation here https://infisical.com/docs/internals/permissions/project-permissions for its usage.
projectSlugstringyesThe slug of the project to create identity specific privilege
slugstringnoThe slug for the new privilege
temporaryAccessEndTimestringnoISO time for which temporary access will end. Computed based on temporaryRange and temporary_access_start_time
temporaryAccessStartTimestringnoISO time for which temporary access should begin. The current time is used by default.
temporaryModestringnoType of temporary access given. Types: relative. Default: relative
temporaryRangestringnoTTL for the temporary time. Eg: 1m, 1h, 1d. Default: 1h

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
identityIdstringnoThe identity id to create identity specific privilege
isTemporarybooleannoFlag to indicate the assigned specific privilege is temporary or not. When isTemporary is true fields temporary_mode,temporaryRange and temporaryAccessStartTime is required.
permissionProjectIdentitySpecificPrivilegePermission (output)no(DEPRECATED, USE permissions_v2. Refer to the migration guide in https://infisical.com/docs/internals/permissions#migrating-from-permission-v1-to-permission-v2) The permissions assigned to the project identity specific privilege
permissionsV2sProjectIdentitySpecificPrivilegePermissionsV2 (output)[]noThe permissions assigned to the project identity specific privilege. Refer to the documentation here https://infisical.com/docs/internals/permissions/project-permissions for its usage.
projectSlugstringnoThe slug of the project to create identity specific privilege
slugstringnoThe slug for the new privilege
temporaryAccessEndTimestringnoISO time for which temporary access will end. Computed based on temporaryRange and temporary_access_start_time
temporaryAccessStartTimestringnoISO time for which temporary access should begin. The current time is used by default.
temporaryModestringnoType of temporary access given. Types: relative. Default: relative
temporaryRangestringnoTTL for the temporary time. Eg: 1m, 1h, 1d. Default: 1h

ProjectIdentitySpecificPrivilegePermission (input)#

Input object ProjectIdentitySpecificPrivilegePermission. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
actionsstring[]yesDescribe what action an entity can take. Enum: create,edit,delete,read
conditionsProjectIdentitySpecificPrivilegePermissionConditions (input)yesThe conditions to scope permissions
subjectstringyesDescribe what action an entity can take. Enum: role,member,groups,settings,integrations,webhooks,service-tokens,environments,tags,audit-logs,ip-allowlist,workspace,secrets,secret-rollback,secret-approval,secret-rotation,identity,certificate-authorities,certificates,certificate-policies,kms,pki-alerts,pki-collections

ProjectIdentitySpecificPrivilegePermissionConditions (input)#

Input object ProjectIdentitySpecificPrivilegePermissionConditions. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
environmentstringyesThe environment slug this permission should allow.
secretPathstringnoThe secret path this permission should be scoped to

ProjectIdentitySpecificPrivilegePermissionsV2 (input)#

Input object ProjectIdentitySpecificPrivilegePermissionsV2. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
actionsstring[]yesDescribe what actions an entity can take.
conditionsstringnoWhen specified, only matching conditions will be allowed to access given resource. Refer to the documentation in https://infisical.com/docs/internals/permissions#conditions for the complete list of supported properties and operators.
invertedbooleannoWhether rule forbids. Set this to true if permission forbids.
subjectstringyesDescribe the entity the permission pertains to.

ProjectIdentitySpecificPrivilegePermission (output)#

Output object ProjectIdentitySpecificPrivilegePermission. Fields below belong to this object.

PropertyTypeAlways presentDescription
actionsstring[]yesDescribe what action an entity can take. Enum: create,edit,delete,read
conditionsProjectIdentitySpecificPrivilegePermissionConditions (output)yesThe conditions to scope permissions
subjectstringyesDescribe what action an entity can take. Enum: role,member,groups,settings,integrations,webhooks,service-tokens,environments,tags,audit-logs,ip-allowlist,workspace,secrets,secret-rollback,secret-approval,secret-rotation,identity,certificate-authorities,certificates,certificate-policies,kms,pki-alerts,pki-collections

ProjectIdentitySpecificPrivilegePermissionConditions (output)#

Output object ProjectIdentitySpecificPrivilegePermissionConditions. Fields below belong to this object.

PropertyTypeAlways presentDescription
environmentstringyesThe environment slug this permission should allow.
secretPathstringnoThe secret path this permission should be scoped to

ProjectIdentitySpecificPrivilegePermissionsV2 (output)#

Output object ProjectIdentitySpecificPrivilegePermissionsV2. Fields below belong to this object.

PropertyTypeAlways presentDescription
actionsstring[]yesDescribe what actions an entity can take.
conditionsstringnoWhen specified, only matching conditions will be allowed to access given resource. Refer to the documentation in https://infisical.com/docs/internals/permissions#conditions for the complete list of supported properties and operators.
invertedbooleanyesWhether rule forbids. Set this to true if permission forbids.
subjectstringyesDescribe the entity the permission pertains to.