Skip to main content

Settings

Resource Settings in pulumi-portainer.
15 min read

Resource Settings in pulumi-portainer.

Pulumi type: portainer:index/settings:Settings.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
addonsCatalogUrlstringnoURL the add-on catalog is fetched from. Business Edition only. Leave unset to keep the built-in catalog.
authenticationMethodnumbernoAuthentication method used by Portainer. 1 = internal, 2 = LDAP, 3 = OAuth.
blackListedLabelsSettingsBlackListedLabel (input)[]noList of container labels that Portainer should hide from the UI.
disableKubeRolesSyncbooleannoWhether automatic synchronization of Kubernetes roles is disabled.
disableKubeShellbooleannoWhether the in-browser Kubernetes shell is disabled for users.
disableKubeconfigDownloadbooleannoWhether downloading kubeconfig files from the Portainer UI is disabled.
displayDonationHeaderbooleannoWhether the donation header banner is shown in the Portainer UI.
displayExternalContributorsbooleannoWhether external contributors are displayed in the Portainer UI.
edgeAgentCheckinIntervalnumbernoHeartbeat interval (in seconds) used by edge agents to poll Portainer.
edgePortainerUrlstringnoPublic URL of the Portainer instance that edge agents use to reach back for polling and tunneling.
enableEdgeComputeFeaturesbooleannoWhether Edge Compute features (edge agents, edge stacks, edge jobs) are enabled.
enableTelemetrybooleannoWhether anonymous usage telemetry is sent to Portainer.
enforceEdgeIdbooleannoWhether Portainer enforces a matching edge identifier when an edge agent connects.
globalDeploymentOptionsSettingsGlobalDeploymentOptions (input)noGlobal deployment options applied across environments.
helmRepositoryUrlstringnoGlobal Helm repository URL used by Portainer for chart browsing.
internalAuthSettingsSettingsInternalAuthSettings (input)noSettings for Portainer's internal authentication provider, such as the password policy.
isDockerDesktopExtensionbooleannoWhether this Portainer instance runs as a Docker Desktop extension.
kubeconfigExpirystringnoValidity period of kubeconfig files generated for users (e.g. "24h", "0" for never).
kubectlShellImagestringnoContainer image used for the in-browser kubectl shell.
ldapSettingsSettingsLdapSettings (input)noConfiguration for the LDAP authentication provider.
logoUrlstringnoURL of a custom logo displayed in the Portainer UI.
oauthSettingsSettingsOauthSettings (input)noConfiguration for the OAuth authentication provider.
settingsIdstringno
snapshotIntervalstringnoInterval at which Portainer snapshots endpoints (e.g. "5m", "1h").
templatesUrlstringnoURL of the JSON file with application templates used by the Portainer UI.
trustOnFirstConnectbooleannoWhether edge agents are automatically trusted on their first connection.
userSessionTimeoutstringnoDuration after which an idle user session expires (e.g. "8h").

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
addonsCatalogUrlstringnoURL the add-on catalog is fetched from. Business Edition only. Leave unset to keep the built-in catalog.
authenticationMethodnumbernoAuthentication method used by Portainer. 1 = internal, 2 = LDAP, 3 = OAuth.
blackListedLabelsSettingsBlackListedLabel (output)[]noList of container labels that Portainer should hide from the UI.
disableKubeRolesSyncbooleannoWhether automatic synchronization of Kubernetes roles is disabled.
disableKubeShellbooleannoWhether the in-browser Kubernetes shell is disabled for users.
disableKubeconfigDownloadbooleannoWhether downloading kubeconfig files from the Portainer UI is disabled.
displayDonationHeaderbooleannoWhether the donation header banner is shown in the Portainer UI.
displayExternalContributorsbooleannoWhether external contributors are displayed in the Portainer UI.
edgeAgentCheckinIntervalnumbernoHeartbeat interval (in seconds) used by edge agents to poll Portainer.
edgePortainerUrlstringnoPublic URL of the Portainer instance that edge agents use to reach back for polling and tunneling.
enableEdgeComputeFeaturesbooleannoWhether Edge Compute features (edge agents, edge stacks, edge jobs) are enabled.
enableTelemetrybooleannoWhether anonymous usage telemetry is sent to Portainer.
enforceEdgeIdbooleannoWhether Portainer enforces a matching edge identifier when an edge agent connects.
globalDeploymentOptionsSettingsGlobalDeploymentOptions (output)noGlobal deployment options applied across environments.
helmRepositoryUrlstringnoGlobal Helm repository URL used by Portainer for chart browsing.
internalAuthSettingsSettingsInternalAuthSettings (output)noSettings for Portainer's internal authentication provider, such as the password policy.
isDockerDesktopExtensionbooleannoWhether this Portainer instance runs as a Docker Desktop extension.
kubeconfigExpirystringnoValidity period of kubeconfig files generated for users (e.g. "24h", "0" for never).
kubectlShellImagestringnoContainer image used for the in-browser kubectl shell.
ldapSettingsSettingsLdapSettings (output)noConfiguration for the LDAP authentication provider.
logoUrlstringnoURL of a custom logo displayed in the Portainer UI.
oauthSettingsSettingsOauthSettings (output)noConfiguration for the OAuth authentication provider.
settingsIdstringno
snapshotIntervalstringnoInterval at which Portainer snapshots endpoints (e.g. "5m", "1h").
templatesUrlstringnoURL of the JSON file with application templates used by the Portainer UI.
trustOnFirstConnectbooleannoWhether edge agents are automatically trusted on their first connection.
userSessionTimeoutstringnoDuration after which an idle user session expires (e.g. "8h").

SettingsBlackListedLabel (input)#

Input object SettingsBlackListedLabel. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
namestringyesName of the container label to hide.
valuestringyesValue of the container label to match for hiding.

SettingsGlobalDeploymentOptions (input)#

Input object SettingsGlobalDeploymentOptions. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
hideStacksFunctionalitybooleannoWhether the stacks functionality is hidden from non-admin users.

SettingsInternalAuthSettings (input)#

Input object SettingsInternalAuthSettings. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
requiredPasswordLengthnumbernoMinimum password length required for internally-managed users.

SettingsLdapSettings (input)#

Input object SettingsLdapSettings. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
anonymousModebooleannoWhether to bind to the LDAP server anonymously instead of using reader credentials.
autoCreateUsersbooleannoWhether Portainer automatically creates a local user record on the first LDAP login.
groupSearchSettingsSettingsLdapSettingsGroupSearchSetting (input)[]noList of LDAP group search configurations used to resolve user group memberships.
passwordstringnoPassword used by the LDAP reader account. Stored in state as a sensitive value.
readerDnstringnoDistinguished Name of the LDAP account used to perform user lookups.
searchSettingsSettingsLdapSettingsSearchSetting (input)[]noList of LDAP user search configurations applied to locate user entries.
startTlsbooleannoWhether to upgrade the LDAP connection to TLS using StartTLS.
tlsConfigSettingsLdapSettingsTlsConfig (input)noTLS configuration used for the LDAP connection.
urlstringnoURL of the LDAP server (e.g. "ldap://ldap.example.com:389").

SettingsLdapSettingsGroupSearchSetting (input)#

Input object SettingsLdapSettingsGroupSearchSetting. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
groupAttributestringnoLDAP attribute on group entries that lists their members.
groupBaseDnstringnoBase DN under which group entries are searched.
groupFilterstringnoLDAP search filter applied when looking up groups.

SettingsLdapSettingsSearchSetting (input)#

Input object SettingsLdapSettingsSearchSetting. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
baseDnstringnoBase DN under which user entries are searched.
filterstringnoLDAP search filter applied when looking up users.
userNameAttributestringnoLDAP attribute used as the user's login name (e.g. "uid", "sAMAccountName").

SettingsLdapSettingsTlsConfig (input)#

Input object SettingsLdapSettingsTlsConfig. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
tlsbooleannoWhether TLS is enabled for the LDAP connection.
tlsCaCertstringnoPEM-encoded CA certificate used to verify the LDAP server certificate.
tlsCertstringnoPEM-encoded client certificate presented to the LDAP server.
tlsKeystringnoPEM-encoded private key matching the client certificate.
tlsSkipVerifybooleannoWhether to skip verification of the LDAP server certificate.

SettingsOauthSettings (input)#

Input object SettingsOauthSettings. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
accessTokenUristringnoToken endpoint URL used to exchange the authorization code for an access token.
authStylenumbernoOAuth client authentication style passed to the token endpoint (0 = auto-detect, 1 = params, 2 = HTTP Basic header).
authorizationUristringnoAuthorization endpoint URL of the OAuth provider.
clientIdstringnoOAuth client identifier registered with the provider.
clientSecretstringnoOAuth client secret. Stored in state as a sensitive value.
defaultTeamIdnumbernoIdentifier of the team that new OAuth users are added to by default. 0 means no default team.
hideInternalAuthbooleannoWhether to hide the internal username/password login form when OAuth is configured.
kubeSecretKeysnumber[]noByte-array key used to encrypt OAuth-derived Kubernetes secrets. Stored in state.
logoutUristringnoURL the user is redirected to after logging out from Portainer.
microsoftTenantIdstringnoMicrosoft Entra/Azure AD tenant identifier used when the OAuth provider is Microsoft.
oauthAutoCreateUsersbooleannoWhether Portainer automatically creates a local user record on the first OAuth login.
oauthAutoMapTeamMembershipsbooleannoWhether Portainer automatically maps Portainer team memberships from OAuth claims.
redirectUristringnoRedirect URI registered with the OAuth provider; must match Portainer's callback URL.
resourceUristringnoResource endpoint URL used to fetch the authenticated user's profile.
scopesstringnoOAuth scopes requested from the provider (space- or comma-separated).
ssobooleannoWhether single sign-on is enabled, redirecting users straight to the OAuth provider.
teamMembershipsSettingsOauthSettingsTeamMemberships (input)noRules that map OAuth claims to Portainer team memberships and admin role.
userIdentifierstringnoClaim used as the unique user identifier from the OAuth provider response.

SettingsOauthSettingsTeamMemberships (input)#

Input object SettingsOauthSettingsTeamMemberships. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
adminAutoPopulatebooleannoWhether Portainer auto-grants admin rights to users whose claim values match the admin regex list.
adminGroupClaimsRegexListsstring[]noList of regular expressions that, when matching a claim value, mark the user as Portainer admin.
oauthClaimMappingsSettingsOauthSettingsTeamMembershipsOauthClaimMapping (input)[]noList of mappings from OAuth claim value regexes to Portainer team IDs.
oauthClaimNamestringnoName of the OAuth claim that carries the user's group/team membership values.

SettingsOauthSettingsTeamMembershipsOauthClaimMapping (input)#

Input object SettingsOauthSettingsTeamMembershipsOauthClaimMapping. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
claimValRegexstringnoRegular expression matched against the OAuth claim value to trigger this mapping.
teamnumbernoIdentifier of the Portainer team that matching users are added to.

SettingsBlackListedLabel (output)#

Output object SettingsBlackListedLabel. Fields below belong to this object.

PropertyTypeAlways presentDescription
namestringyesName of the container label to hide.
valuestringyesValue of the container label to match for hiding.

SettingsGlobalDeploymentOptions (output)#

Output object SettingsGlobalDeploymentOptions. Fields below belong to this object.

PropertyTypeAlways presentDescription
hideStacksFunctionalitybooleanyesWhether the stacks functionality is hidden from non-admin users.

SettingsInternalAuthSettings (output)#

Output object SettingsInternalAuthSettings. Fields below belong to this object.

PropertyTypeAlways presentDescription
requiredPasswordLengthnumberyesMinimum password length required for internally-managed users.

SettingsLdapSettings (output)#

Output object SettingsLdapSettings. Fields below belong to this object.

PropertyTypeAlways presentDescription
anonymousModebooleanyesWhether to bind to the LDAP server anonymously instead of using reader credentials.
autoCreateUsersbooleanyesWhether Portainer automatically creates a local user record on the first LDAP login.
groupSearchSettingsSettingsLdapSettingsGroupSearchSetting (output)[]noList of LDAP group search configurations used to resolve user group memberships.
passwordstringyesPassword used by the LDAP reader account. Stored in state as a sensitive value.
readerDnstringyesDistinguished Name of the LDAP account used to perform user lookups.
searchSettingsSettingsLdapSettingsSearchSetting (output)[]noList of LDAP user search configurations applied to locate user entries.
startTlsbooleanyesWhether to upgrade the LDAP connection to TLS using StartTLS.
tlsConfigSettingsLdapSettingsTlsConfig (output)noTLS configuration used for the LDAP connection.
urlstringyesURL of the LDAP server (e.g. "ldap://ldap.example.com:389").

SettingsLdapSettingsGroupSearchSetting (output)#

Output object SettingsLdapSettingsGroupSearchSetting. Fields below belong to this object.

PropertyTypeAlways presentDescription
groupAttributestringyesLDAP attribute on group entries that lists their members.
groupBaseDnstringyesBase DN under which group entries are searched.
groupFilterstringyesLDAP search filter applied when looking up groups.

SettingsLdapSettingsSearchSetting (output)#

Output object SettingsLdapSettingsSearchSetting. Fields below belong to this object.

PropertyTypeAlways presentDescription
baseDnstringyesBase DN under which user entries are searched.
filterstringyesLDAP search filter applied when looking up users.
userNameAttributestringyesLDAP attribute used as the user's login name (e.g. "uid", "sAMAccountName").

SettingsLdapSettingsTlsConfig (output)#

Output object SettingsLdapSettingsTlsConfig. Fields below belong to this object.

PropertyTypeAlways presentDescription
tlsbooleanyesWhether TLS is enabled for the LDAP connection.
tlsCaCertstringyesPEM-encoded CA certificate used to verify the LDAP server certificate.
tlsCertstringyesPEM-encoded client certificate presented to the LDAP server.
tlsKeystringyesPEM-encoded private key matching the client certificate.
tlsSkipVerifybooleanyesWhether to skip verification of the LDAP server certificate.

SettingsOauthSettings (output)#

Output object SettingsOauthSettings. Fields below belong to this object.

PropertyTypeAlways presentDescription
accessTokenUristringyesToken endpoint URL used to exchange the authorization code for an access token.
authStylenumberyesOAuth client authentication style passed to the token endpoint (0 = auto-detect, 1 = params, 2 = HTTP Basic header).
authorizationUristringyesAuthorization endpoint URL of the OAuth provider.
clientIdstringyesOAuth client identifier registered with the provider.
clientSecretstringyesOAuth client secret. Stored in state as a sensitive value.
defaultTeamIdnumberyesIdentifier of the team that new OAuth users are added to by default. 0 means no default team.
hideInternalAuthbooleanyesWhether to hide the internal username/password login form when OAuth is configured.
kubeSecretKeysnumber[]yesByte-array key used to encrypt OAuth-derived Kubernetes secrets. Stored in state.
logoutUristringyesURL the user is redirected to after logging out from Portainer.
microsoftTenantIdstringyesMicrosoft Entra/Azure AD tenant identifier used when the OAuth provider is Microsoft.
oauthAutoCreateUsersbooleanyesWhether Portainer automatically creates a local user record on the first OAuth login.
oauthAutoMapTeamMembershipsbooleanyesWhether Portainer automatically maps Portainer team memberships from OAuth claims.
redirectUristringyesRedirect URI registered with the OAuth provider; must match Portainer's callback URL.
resourceUristringyesResource endpoint URL used to fetch the authenticated user's profile.
scopesstringyesOAuth scopes requested from the provider (space- or comma-separated).
ssobooleanyesWhether single sign-on is enabled, redirecting users straight to the OAuth provider.
teamMembershipsSettingsOauthSettingsTeamMemberships (output)noRules that map OAuth claims to Portainer team memberships and admin role.
userIdentifierstringyesClaim used as the unique user identifier from the OAuth provider response.

SettingsOauthSettingsTeamMemberships (output)#

Output object SettingsOauthSettingsTeamMemberships. Fields below belong to this object.

PropertyTypeAlways presentDescription
adminAutoPopulatebooleanyesWhether Portainer auto-grants admin rights to users whose claim values match the admin regex list.
adminGroupClaimsRegexListsstring[]yesList of regular expressions that, when matching a claim value, mark the user as Portainer admin.
oauthClaimMappingsSettingsOauthSettingsTeamMembershipsOauthClaimMapping (output)[]noList of mappings from OAuth claim value regexes to Portainer team IDs.
oauthClaimNamestringyesName of the OAuth claim that carries the user's group/team membership values.

SettingsOauthSettingsTeamMembershipsOauthClaimMapping (output)#

Output object SettingsOauthSettingsTeamMembershipsOauthClaimMapping. Fields below belong to this object.

PropertyTypeAlways presentDescription
claimValRegexstringyesRegular expression matched against the OAuth claim value to trigger this mapping.
teamnumberyesIdentifier of the Portainer team that matching users are added to.