Skip to main content

Stack

Resource Stack in pulumi-portainer.
11 min read

Resource Stack in pulumi-portainer.

Pulumi type: portainer:index/stack:Stack.

name is the Pulumi resource name. Nested object fields are documented under that object. They are not arguments of this resource.

Example#

Only required arguments are set. A string in angle brackets stands in for that argument. Any other value is an option or example written in the SDK description.

Arguments#

PropertyTypeRequiredDescription
activebooleannoWhether the stack should be running. Set to false to stop the stack.
additionalFilesstring[]noList of additional Compose file paths to use when deploying from Git repository.
additionalHelmValuesFilesstring[]noList of additional Helm values files (e.g. values-prod.yaml). Only used with helm_chart_path.
authorizedTeamsnumber[]noList of team IDs authorized to access this stack (only if ownership is restricted).
authorizedUsersnumber[]noList of user IDs authorized to access this stack (only if ownership is restricted).
composeFormatbooleannoWhether the supplied content is in Docker Compose format (true) instead of native Kubernetes manifest (false). Only applies to Kubernetes stacks. Changing this value forces resource recreation.
deploymentTypestringyesDeployment mode: 'standalone', 'swarm', or 'kubernetes'
endpointIdnumberyesIdentifier of the Portainer environment (endpoint) where the stack will be deployed. Changing this value forces resource recreation.
envsStackEnv (input)[]noList of environment variables injected into the stack at deploy time.
filePathInRepositorystringnoPath to Compose/manifest file in the repository. Defaults to docker-compose.yml for Docker/Swarm stacks. Not required when helmChartPath is set.
filesystemPathstringnoLocal filesystem path on the host used when supportRelativePath is true. Maps to the repository working directory.
forceUpdatebooleannoWhether to prune unused services/networks during stack update (default: true)
gitRepositoryAuthenticationbooleannoWhether the Git repository requires authentication. When true,repositoryUsername and repositoryPassword(or their write-only equivalents) are sent to Portainer.
helmChartPathstringnoPath to a Helm chart folder in the Git repository (must contain Chart.yaml). Only used when deploymentType is 'kubernetes' and method is 'repository'.
manifestUrlstringnoURL to a remote Kubernetes manifest used when deploymentType is 'kubernetes' and method is 'url'. Changing this value forces resource recreation.
methodstringyesCreation method: 'string', 'file', 'repository', or 'url'
namestringnoName of the Portainer stack. Must be unique within the target endpoint. Changing this value forces resource recreation.
namespacestringnoKubernetes namespace used when deploymentType is 'kubernetes'. Changing this value forces resource recreation.
ownershipstringnoOwnership level: 'public', 'administrators' or 'restricted'.
prunebooleannoWhether to prune unused services/networks during stack update (default: false)
pullImagebooleannoWhether to force pull latest images during stack update (default: true)
registriesnumber[]noList of registry IDs allowed for this stack.
repositoryGitCredentialIdnumbernoID of the shared Git credentials to use for authentication (Portainer < 2.43). Replaced by 'source_id' in Portainer 2.43 STS, which switched to the Sources model; on 2.43+ this field is ignored. Both are sent, so a single configuration stays compatible with old and new Portainer.
repositoryPasswordstringnoPassword or personal access token used to authenticate against the Git repository. Stored in state as a sensitive value.
repositoryPasswordWostringnoNOTE: This field is write-only and its value will not be updated in state as part of read operations. Write-only repository password (supports ephemeral values; not stored in Terraform state).
repositoryReferenceNamestringnoGit reference (branch or tag) used by Portainer when deploying from the repository. Defaults to refs/heads/main.
repositoryUrlstringnoURL of the Git repository used to deploy the stack when method is 'repository'. Changing this value forces resource recreation.
repositoryUrlWostringnoNOTE: This field is write-only and its value will not be updated in state as part of read operations. Write-only repository URL (supports ephemeral values; not stored in Terraform state).
repositoryUsernamestringnoUsername used to authenticate against the Git repository.
repositoryUsernameWostringnoNOTE: This field is write-only and its value will not be updated in state as part of read operations. Write-only repository username (supports ephemeral values).
repositoryWoVersionnumbernoVersion flag for write-only repository credentials; increment to trigger recreation.
sourceIdnumbernoID of a Portainer Source (Git source) providing the repository URL and credentials. Introduced in Portainer 2.43 STS, which replaced 'repository_git_credential_id'. When set (non-zero), Portainer resolves the repository URL/credentials from the referenced Source and ignores the inline repository_username/repository_password and repositoryGitCredentialId fields.
stackFileContentstringnoInline Compose or Kubernetes manifest content used to deploy the stack. Required when method is 'string'; populated from stackFilePath when method is 'file'.
stackFilePathstringnoLocal filesystem path to a Compose or manifest file. Contents are read and uploaded to Portainer when method is 'file'.
stackIdstringno
stackWebhookbooleannoEnable autoUpdate webhook (GitOps).
supportRelativePathbooleannoWhether Portainer should support relative paths inside the Compose file for bind mounts referencing repository contents. Changing this value forces resource recreation.
swarmIdstringnoIdentifier of the Docker Swarm cluster used when deploymentType is 'swarm'. Automatically fetched from Portainer when not provided. Changing this value forces resource recreation.
timeoutsStackTimeouts (input)no
tlsskipVerifybooleannoWhether to skip TLS verification when Portainer connects to the Git repository. Changing this value forces resource recreation.
updateIntervalstringnoGitOps auto-update polling interval (e.g. '5m', '1h'). When set, Portainer periodically checks the Git repository for changes and redeploys the stack.

Outputs#

Computed outputs are produced by the provider. They are not constructor arguments.

PropertyTypeComputedDescription
activebooleannoWhether the stack should be running. Set to false to stop the stack.
additionalFilesstring[]noList of additional Compose file paths to use when deploying from Git repository.
additionalHelmValuesFilesstring[]noList of additional Helm values files (e.g. values-prod.yaml). Only used with helm_chart_path.
authorizedTeamsnumber[]noList of team IDs authorized to access this stack (only if ownership is restricted).
authorizedUsersnumber[]noList of user IDs authorized to access this stack (only if ownership is restricted).
composeFormatbooleannoWhether the supplied content is in Docker Compose format (true) instead of native Kubernetes manifest (false). Only applies to Kubernetes stacks. Changing this value forces resource recreation.
deploymentTypestringnoDeployment mode: 'standalone', 'swarm', or 'kubernetes'
endpointIdnumbernoIdentifier of the Portainer environment (endpoint) where the stack will be deployed. Changing this value forces resource recreation.
envsStackEnv (output)[]noList of environment variables injected into the stack at deploy time.
filePathInRepositorystringnoPath to Compose/manifest file in the repository. Defaults to docker-compose.yml for Docker/Swarm stacks. Not required when helmChartPath is set.
filesystemPathstringnoLocal filesystem path on the host used when supportRelativePath is true. Maps to the repository working directory.
forceUpdatebooleannoWhether to prune unused services/networks during stack update (default: true)
gitRepositoryAuthenticationbooleannoWhether the Git repository requires authentication. When true,repositoryUsername and repositoryPassword(or their write-only equivalents) are sent to Portainer.
helmChartPathstringnoPath to a Helm chart folder in the Git repository (must contain Chart.yaml). Only used when deploymentType is 'kubernetes' and method is 'repository'.
manifestUrlstringnoURL to a remote Kubernetes manifest used when deploymentType is 'kubernetes' and method is 'url'. Changing this value forces resource recreation.
methodstringnoCreation method: 'string', 'file', 'repository', or 'url'
namestringnoName of the Portainer stack. Must be unique within the target endpoint. Changing this value forces resource recreation.
namespacestringnoKubernetes namespace used when deploymentType is 'kubernetes'. Changing this value forces resource recreation.
ownershipstringnoOwnership level: 'public', 'administrators' or 'restricted'.
prunebooleannoWhether to prune unused services/networks during stack update (default: false)
pullImagebooleannoWhether to force pull latest images during stack update (default: true)
registriesnumber[]noList of registry IDs allowed for this stack.
repositoryGitCredentialIdnumbernoID of the shared Git credentials to use for authentication (Portainer < 2.43). Replaced by 'source_id' in Portainer 2.43 STS, which switched to the Sources model; on 2.43+ this field is ignored. Both are sent, so a single configuration stays compatible with old and new Portainer.
repositoryPasswordstringnoPassword or personal access token used to authenticate against the Git repository. Stored in state as a sensitive value.
repositoryPasswordWostringnoNOTE: This field is write-only and its value will not be updated in state as part of read operations. Write-only repository password (supports ephemeral values; not stored in Terraform state).
repositoryReferenceNamestringnoGit reference (branch or tag) used by Portainer when deploying from the repository. Defaults to refs/heads/main.
repositoryUrlstringnoURL of the Git repository used to deploy the stack when method is 'repository'. Changing this value forces resource recreation.
repositoryUrlWostringnoNOTE: This field is write-only and its value will not be updated in state as part of read operations. Write-only repository URL (supports ephemeral values; not stored in Terraform state).
repositoryUsernamestringnoUsername used to authenticate against the Git repository.
repositoryUsernameWostringnoNOTE: This field is write-only and its value will not be updated in state as part of read operations. Write-only repository username (supports ephemeral values).
repositoryWoVersionnumbernoVersion flag for write-only repository credentials; increment to trigger recreation.
resourceControlIdnumberyesIdentifier of the Portainer resource control entry associated with the stack. Computed by Portainer.
sourceIdnumbernoID of a Portainer Source (Git source) providing the repository URL and credentials. Introduced in Portainer 2.43 STS, which replaced 'repository_git_credential_id'. When set (non-zero), Portainer resolves the repository URL/credentials from the referenced Source and ignores the inline repository_username/repository_password and repositoryGitCredentialId fields.
stackFileContentstringnoInline Compose or Kubernetes manifest content used to deploy the stack. Required when method is 'string'; populated from stackFilePath when method is 'file'.
stackFilePathstringnoLocal filesystem path to a Compose or manifest file. Contents are read and uploaded to Portainer when method is 'file'.
stackIdstringno
stackWebhookbooleannoEnable autoUpdate webhook (GitOps).
supportRelativePathbooleannoWhether Portainer should support relative paths inside the Compose file for bind mounts referencing repository contents. Changing this value forces resource recreation.
swarmIdstringnoIdentifier of the Docker Swarm cluster used when deploymentType is 'swarm'. Automatically fetched from Portainer when not provided. Changing this value forces resource recreation.
timeoutsStackTimeouts (output)no
tlsskipVerifybooleannoWhether to skip TLS verification when Portainer connects to the Git repository. Changing this value forces resource recreation.
updateIntervalstringnoGitOps auto-update polling interval (e.g. '5m', '1h'). When set, Portainer periodically checks the Git repository for changes and redeploys the stack.
webhookIdstringyesUUID of the GitOps webhook (read-only).
webhookUrlstringyesFull URL of the webhook trigger

StackEnv (input)#

Input object StackEnv. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
namestringyesName of the environment variable.
valuestringyesValue of the environment variable.

StackTimeouts (input)#

Input object StackTimeouts. Fields below belong to this object, not to the parent.

PropertyTypeRequiredDescription
createstringno
deletestringno
updatestringno

StackEnv (output)#

Output object StackEnv. Fields below belong to this object.

PropertyTypeAlways presentDescription
namestringyesName of the environment variable.
valuestringyesValue of the environment variable.

StackTimeouts (output)#

Output object StackTimeouts. Fields below belong to this object.

PropertyTypeAlways presentDescription
createstringno
deletestringno
updatestringno