Resource SecretApprovalPolicy in pulumi-infisical.
Pulumi type: infisical:index/secretApprovalPolicy:SecretApprovalPolicy.
name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.
Example#
Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.
Arguments#
| Property | Type | Required | Description |
|---|---|---|---|
allowSelfApproval | boolean | no | Whether to allow the approvers to approve their own changes |
approvers | SecretApprovalPolicyApprover (input)[] | yes | The required approvers |
bypassApprovalsForMachineIdentities | boolean | no | Whether machine identities can bypass the policy. If not set, the Infisical default is used on creation and the current value is left unchanged on update |
bypassers | SecretApprovalPolicyBypasser (input)[] | no | The bypassers who can bypass the approval policy |
enforcementLevel | string | no | The enforcement level of the policy. This can either be hard or soft |
environmentSlug | string | no | (DEPRECATED, Use environmentSlugs instead) The environment to apply the secret approval policy to |
environmentSlugs | string[] | no | The environments to apply the secret approval policy to |
name | string | no | The name of the secret approval policy |
projectId | string | yes | The ID of the project to add the secret approval policy |
requiredApprovals | number | yes | The number of required approvers |
secretPath | string | yes | The secret path to apply the secret approval policy to |
Outputs#
Computed outputs are produced by the provider. They are not constructor arguments.
| Property | Type | Computed | Description |
|---|---|---|---|
allowSelfApproval | boolean | no | Whether to allow the approvers to approve their own changes |
approvers | SecretApprovalPolicyApprover (output)[] | no | The required approvers |
bypassApprovalsForMachineIdentities | boolean | no | Whether machine identities can bypass the policy. If not set, the Infisical default is used on creation and the current value is left unchanged on update |
bypassers | SecretApprovalPolicyBypasser (output)[] | no | The bypassers who can bypass the approval policy |
enforcementLevel | string | no | The enforcement level of the policy. This can either be hard or soft |
environmentSlug | string | no | (DEPRECATED, Use environmentSlugs instead) The environment to apply the secret approval policy to |
environmentSlugs | string[] | no | The environments to apply the secret approval policy to |
name | string | no | The name of the secret approval policy |
projectId | string | no | The ID of the project to add the secret approval policy |
requiredApprovals | number | no | The number of required approvers |
secretPath | string | no | The secret path to apply the secret approval policy to |
SecretApprovalPolicyApprover (input)#
Input object SecretApprovalPolicyApprover. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
id | string | no | The ID of the approver |
type | string | yes | The type of approver. Either group or user |
username | string | no | The username of the approver. By default, this is the email |
SecretApprovalPolicyBypasser (input)#
Input object SecretApprovalPolicyBypasser. Fields below belong to this object, not to the parent.
| Property | Type | Required | Description |
|---|---|---|---|
id | string | no | The ID of the bypasser |
type | string | yes | The type of bypasser. Either group or user |
username | string | no | The username of the bypasser. By default, this is the email |
SecretApprovalPolicyApprover (output)#
Output object SecretApprovalPolicyApprover. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
id | string | no | The ID of the approver |
type | string | yes | The type of approver. Either group or user |
username | string | no | The username of the approver. By default, this is the email |
SecretApprovalPolicyBypasser (output)#
Output object SecretApprovalPolicyBypasser. Fields below belong to this object.
| Property | Type | Always present | Description |
|---|---|---|---|
id | string | no | The ID of the bypasser |
type | string | yes | The type of bypasser. Either group or user |
username | string | no | The username of the bypasser. By default, this is the email |