# SecretApprovalPolicy

> Resource SecretApprovalPolicy in pulumi-infisical.

<!-- Generated from the pulumi-infisical SDK. -->

Resource SecretApprovalPolicy in pulumi-infisical.

Pulumi type: `infisical:index/secretApprovalPolicy:SecretApprovalPolicy`.

`name` is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

## Example

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

```ts
import * as infisical from "pulumi-infisical"

const resource = new infisical.SecretApprovalPolicy("secretApprovalPolicy", {
  approvers: [
    {
      type: "<type>",
    },
  ],
  projectId: "<projectId>",
  requiredApprovals: 0,
  secretPath: "<secretPath>",
})
```

## Arguments

| Property                              | Type                                     | Required | Description                                                                                                                                               |
| ------------------------------------- | ---------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `allowSelfApproval`                   | `boolean`                                | no       | Whether to allow the approvers to approve their own changes                                                                                               |
| `approvers`                           | `SecretApprovalPolicyApprover (input)[]` | yes      | The required approvers                                                                                                                                    |
| `bypassApprovalsForMachineIdentities` | `boolean`                                | no       | Whether machine identities can bypass the policy. If not set, the Infisical default is used on creation and the current value is left unchanged on update |
| `bypassers`                           | `SecretApprovalPolicyBypasser (input)[]` | no       | The bypassers who can bypass the approval policy                                                                                                          |
| `enforcementLevel`                    | `string`                                 | no       | The enforcement level of the policy. This can either be hard or soft                                                                                      |
| `environmentSlug`                     | `string`                                 | no       | (DEPRECATED, Use `environmentSlugs` instead) The environment to apply the secret approval policy to                                                       |
| `environmentSlugs`                    | `string[]`                               | no       | The environments to apply the secret approval policy to                                                                                                   |
| `name`                                | `string`                                 | no       | The name of the secret approval policy                                                                                                                    |
| `projectId`                           | `string`                                 | yes      | The ID of the project to add the secret approval policy                                                                                                   |
| `requiredApprovals`                   | `number`                                 | yes      | The number of required approvers                                                                                                                          |
| `secretPath`                          | `string`                                 | yes      | The secret path to apply the secret approval policy to                                                                                                    |

## Outputs

Computed outputs are produced by the provider. They are not constructor arguments.

| Property                              | Type                                      | Computed | Description                                                                                                                                               |
| ------------------------------------- | ----------------------------------------- | -------- | --------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `allowSelfApproval`                   | `boolean`                                 | no       | Whether to allow the approvers to approve their own changes                                                                                               |
| `approvers`                           | `SecretApprovalPolicyApprover (output)[]` | no       | The required approvers                                                                                                                                    |
| `bypassApprovalsForMachineIdentities` | `boolean`                                 | no       | Whether machine identities can bypass the policy. If not set, the Infisical default is used on creation and the current value is left unchanged on update |
| `bypassers`                           | `SecretApprovalPolicyBypasser (output)[]` | no       | The bypassers who can bypass the approval policy                                                                                                          |
| `enforcementLevel`                    | `string`                                  | no       | The enforcement level of the policy. This can either be hard or soft                                                                                      |
| `environmentSlug`                     | `string`                                  | no       | (DEPRECATED, Use `environmentSlugs` instead) The environment to apply the secret approval policy to                                                       |
| `environmentSlugs`                    | `string[]`                                | no       | The environments to apply the secret approval policy to                                                                                                   |
| `name`                                | `string`                                  | no       | The name of the secret approval policy                                                                                                                    |
| `projectId`                           | `string`                                  | no       | The ID of the project to add the secret approval policy                                                                                                   |
| `requiredApprovals`                   | `number`                                  | no       | The number of required approvers                                                                                                                          |
| `secretPath`                          | `string`                                  | no       | The secret path to apply the secret approval policy to                                                                                                    |

## `SecretApprovalPolicyApprover (input)`

Input object `SecretApprovalPolicyApprover`. Fields below belong to this object, not to the parent.

| Property   | Type     | Required | Description                                                 |
| ---------- | -------- | -------- | ----------------------------------------------------------- |
| `id`       | `string` | no       | The ID of the approver                                      |
| `type`     | `string` | yes      | The type of approver. Either group or user                  |
| `username` | `string` | no       | The username of the approver. By default, this is the email |

## `SecretApprovalPolicyBypasser (input)`

Input object `SecretApprovalPolicyBypasser`. Fields below belong to this object, not to the parent.

| Property   | Type     | Required | Description                                                 |
| ---------- | -------- | -------- | ----------------------------------------------------------- |
| `id`       | `string` | no       | The ID of the bypasser                                      |
| `type`     | `string` | yes      | The type of bypasser. Either group or user                  |
| `username` | `string` | no       | The username of the bypasser. By default, this is the email |

## `SecretApprovalPolicyApprover (output)`

Output object `SecretApprovalPolicyApprover`. Fields below belong to this object.

| Property   | Type     | Always present | Description                                                 |
| ---------- | -------- | -------------- | ----------------------------------------------------------- |
| `id`       | `string` | no             | The ID of the approver                                      |
| `type`     | `string` | yes            | The type of approver. Either group or user                  |
| `username` | `string` | no             | The username of the approver. By default, this is the email |

## `SecretApprovalPolicyBypasser (output)`

Output object `SecretApprovalPolicyBypasser`. Fields below belong to this object.

| Property   | Type     | Always present | Description                                                 |
| ---------- | -------- | -------------- | ----------------------------------------------------------- |
| `id`       | `string` | no             | The ID of the bypasser                                      |
| `type`     | `string` | yes            | The type of bypasser. Either group or user                  |
| `username` | `string` | no             | The username of the bypasser. By default, this is the email |
