Skip to main content

ProjectRole

Resource ProjectRole in pulumi-infisical.
4 min read

Resource ProjectRole in pulumi-infisical.

Pulumi type: infisical:index/projectRole:ProjectRole.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
descriptionstringnoThe description for the new role. Defaults to an empty string.
namestringnoThe name for the new role
permissionsProjectRolePermission (input)[]no(DEPRECATED, USE permissions_v2. Refer to the migration guide in https://infisical.com/docs/internals/permissions#migrating-from-permission-v1-to-permission-v2) The permissions assigned to the project role
permissionsV2sProjectRolePermissionsV2 (input)[]noThe permissions assigned to the project role. Refer to the documentation here https://infisical.com/docs/internals/permissions/project-permissions for its usage.
projectIdstringnoThe ID of the project to create role. Must provide either projectId or project_slug, but not both.
projectSlugstringnoThe slug of the project to create role. Must provide either projectSlug or project_id, but not both.
slugstringyesThe slug for the new role

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
descriptionstringnoThe description for the new role. Defaults to an empty string.
namestringnoThe name for the new role
permissionsProjectRolePermission (output)[]no(DEPRECATED, USE permissions_v2. Refer to the migration guide in https://infisical.com/docs/internals/permissions#migrating-from-permission-v1-to-permission-v2) The permissions assigned to the project role
permissionsV2sProjectRolePermissionsV2 (output)[]noThe permissions assigned to the project role. Refer to the documentation here https://infisical.com/docs/internals/permissions/project-permissions for its usage.
projectIdstringnoThe ID of the project to create role. Must provide either projectId or project_slug, but not both.
projectSlugstringnoThe slug of the project to create role. Must provide either projectSlug or project_id, but not both.
slugstringnoThe slug for the new role

ProjectRolePermission (input)#

Input object ProjectRolePermission. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
actionstringyesDescribe what action an entity can take. Enum: create,edit,delete,read
conditionsProjectRolePermissionConditions (input)noThe conditions to scope permissions
subjectstringyesDescribe what action an entity can take. Enum: role,member,groups,settings,integrations,webhooks,service-tokens,environments,tags,audit-logs,ip-allowlist,workspace,secrets,secret-rollback,secret-approval,secret-rotation,identity,certificate-authorities,certificates,certificate-policies,kms,pki-alerts,pki-collections

ProjectRolePermissionConditions (input)#

Input object ProjectRolePermissionConditions. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
environmentstringnoThe environment slug this permission should allow.
secretPathstringnoThe secret path this permission should be scoped to

ProjectRolePermissionsV2 (input)#

Input object ProjectRolePermissionsV2. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
actionsstring[]yesDescribe what actions an entity can take.
conditionsstringnoWhen specified, only matching conditions will be allowed to access given resource. Refer to the documentation in https://infisical.com/docs/internals/permissions#conditions for the complete list of supported properties and operators.
invertedbooleannoWhether rule forbids. Set this to true if permission forbids.
subjectstringyesDescribe the entity the permission pertains to.

ProjectRolePermission (output)#

Output object ProjectRolePermission. Fields below belong to this object.

PropertyTypeAlways presentDescription
actionstringyesDescribe what action an entity can take. Enum: create,edit,delete,read
conditionsProjectRolePermissionConditions (output)noThe conditions to scope permissions
subjectstringyesDescribe what action an entity can take. Enum: role,member,groups,settings,integrations,webhooks,service-tokens,environments,tags,audit-logs,ip-allowlist,workspace,secrets,secret-rollback,secret-approval,secret-rotation,identity,certificate-authorities,certificates,certificate-policies,kms,pki-alerts,pki-collections

ProjectRolePermissionConditions (output)#

Output object ProjectRolePermissionConditions. Fields below belong to this object.

PropertyTypeAlways presentDescription
environmentstringnoThe environment slug this permission should allow.
secretPathstringnoThe secret path this permission should be scoped to

ProjectRolePermissionsV2 (output)#

Output object ProjectRolePermissionsV2. Fields below belong to this object.

PropertyTypeAlways presentDescription
actionsstring[]yesDescribe what actions an entity can take.
conditionsstringnoWhen specified, only matching conditions will be allowed to access given resource. Refer to the documentation in https://infisical.com/docs/internals/permissions#conditions for the complete list of supported properties and operators.
invertedbooleanyesWhether rule forbids. Set this to true if permission forbids.
subjectstringyesDescribe the entity the permission pertains to.