import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * The ACM certificate resource allows requesting and management of certificates * from the Amazon Certificate Manager. * * ACM certificates can be created in three ways: * Amazon-issued, where AWS provides the certificate authority and automatically manages renewal; * imported certificates, issued by another certificate authority; * and private certificates, issued using an ACM Private Certificate Authority. * * For Amazon-issued certificates, this resource deals with requesting certificates and managing their attributes and life-cycle. It does not wait for a certificate to be issued — use `aws.acm.CertificateValidation` for that. Most commonly used together with `aws.route53.Record` and `aws.acm.CertificateValidation` to request a DNS validated certificate, deploy the required validation records, and wait for validation to complete. It's recommended to specify `createBeforeDestroy = true` in a lifecycle block to replace a certificate which is currently in use (e.g., by `aws.lb.Listener`). * * Imported certificates can be used to make certificates created with an external certificate authority available for AWS services. As they are not managed by AWS, imported certificates are not eligible for automatic renewal. New certificate materials can be supplied to an existing imported certificate to update it in place. * * Private certificates are issued by an ACM Private Certificate Authority, which can be created using `aws.acmpca.CertificateAuthority`. Private certificates created using this resource are eligible for managed renewal if they have been exported or associated with another AWS service. See [managed renewal documentation](https://docs.aws.amazon.com/acm/latest/userguide/managed-renewal.html) for more information. By default, a certificate is valid for 395 days and the managed renewal process will start 60 days before expiration. To renew the certificate earlier than 60 days before expiration, configure `earlyRenewalDuration`. * * ## Example Usage * * ### Custom Domain Validation Options * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const cert = new aws.acm.Certificate("cert", { * validationOptions: [{ * domainName: "testing.example.com", * validationDomain: "example.com", * }], * domainName: "testing.example.com", * validationMethod: "EMAIL", * }); * ``` * * ### Existing Certificate Body Import * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * import * as tls from "@pulumi/tls"; * * const example = new tls.PrivateKey("example", {algorithm: "RSA"}); * const exampleSelfSignedCert = new tls.SelfSignedCert("example", { * subject: [{ * commonName: "example.com", * organization: "ACME Examples, Inc", * }], * keyAlgorithm: "RSA", * privateKeyPem: example.privateKeyPem, * validityPeriodHours: 12, * allowedUses: [ * "key_encipherment", * "digital_signature", * "server_auth", * ], * }); * const cert = new aws.acm.Certificate("cert", { * privateKey: example.privateKeyPem, * certificateBody: exampleSelfSignedCert.certPem, * }); * ``` * * ### Existing Certificate Body Import With Write-Only Private Key * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * import * as tls from "@pulumi/tls"; * * const example = new tls.PrivateKey("example", {algorithm: "RSA"}); * const exampleSelfSignedCert = new tls.SelfSignedCert("example", { * subject: [{ * commonName: "example.com", * organization: "ACME Examples, Inc", * }], * keyAlgorithm: "RSA", * privateKeyPem: example.privateKeyPem, * validityPeriodHours: 12, * allowedUses: [ * "key_encipherment", * "digital_signature", * "server_auth", * ], * }); * const cert = new aws.acm.Certificate("cert", { * privateKeyWo: example.privateKeyPem, * privateKeyWoVersion: 1, * certificateBody: exampleSelfSignedCert.certPem, * }); * ``` * * ### Referencing domainValidationOptions With forEach Based Resources * * See the `aws.acm.CertificateValidation` resource for a full example of performing DNS validation. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example: {[key: string]: aws.route53.Record} = {}; * for (const range of Object.entries(.reduce((__obj, dvo) => ({ ...__obj, [dvo.domainName]: { * name: dvo.resourceRecordName, * record: dvo.resourceRecordValue, * type: dvo.resourceRecordType, * } }), {})).sort().map(([k, v]) => ({key: k, value: v}))) { * example[range.key] = new aws.route53.Record(`example-${range.key}`, { * allowOverwrite: true, * name: range.value.name, * records: [range.value.record], * ttl: 60, * type: aws.route53.RecordType[range.value.type], * zoneId: exampleAwsRoute53Zone.zoneId, * }); * } * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `arn` (String) ARN of the certificate. * * Using `pulumi import`, import certificates using their ARN. For example: * * ```sh * $ pulumi import aws:acm/certificate:Certificate example arn:aws:acm:eu-central-1:123456789012:certificate/7e7a28d2-163f-4b8f-b9cd-822f96c08d6a * ``` */ export declare class Certificate extends pulumi.CustomResource { /** * Get an existing Certificate resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: CertificateState, opts?: pulumi.CustomResourceOptions): Certificate; /** * Returns true if the given object is an instance of Certificate. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is Certificate; /** * ARN of the certificate */ readonly arn: pulumi.Output; readonly certificateAuthorityArn: pulumi.Output; readonly certificateBody: pulumi.Output; readonly certificateChain: pulumi.Output; /** * Domain to be validated */ readonly domainName: pulumi.Output; /** * Set of domain validation objects which can be used to complete certificate validation. * Can have more than one element, e.g., if SANs are defined. * Only set if `DNS`-validation was used. */ readonly domainValidationOptions: pulumi.Output; readonly earlyRenewalDuration: pulumi.Output; readonly keyAlgorithm: pulumi.Output; /** * Expiration date and time of the certificate. */ readonly notAfter: pulumi.Output; /** * Start of the validity period of the certificate. */ readonly notBefore: pulumi.Output; readonly options: pulumi.Output; /** * `true` if a Private certificate eligible for managed renewal is within the `earlyRenewalDuration` period. */ readonly pendingRenewal: pulumi.Output; readonly privateKey: pulumi.Output; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. */ readonly privateKeyWo: pulumi.Output; readonly privateKeyWoVersion: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. * * Creating an Amazon issued certificate */ readonly region: pulumi.Output; /** * Whether the certificate is eligible for managed renewal. */ readonly renewalEligibility: pulumi.Output; /** * Contains information about the status of ACM's [managed renewal](https://docs.aws.amazon.com/acm/latest/userguide/acm-renewal.html) for the certificate. */ readonly renewalSummaries: pulumi.Output; /** * Status of the certificate. */ readonly status: pulumi.Output; readonly subjectAlternativeNames: pulumi.Output; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; /** * Source of the certificate. */ readonly type: pulumi.Output; /** * List of addresses that received a validation email. Only set if `EMAIL` validation was used. */ readonly validationEmails: pulumi.Output; readonly validationMethod: pulumi.Output; readonly validationOptions: pulumi.Output; /** * Create a Certificate resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args?: CertificateArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering Certificate resources. */ export interface CertificateState { /** * ARN of the certificate */ arn?: pulumi.Input; certificateAuthorityArn?: pulumi.Input; certificateBody?: pulumi.Input; certificateChain?: pulumi.Input; /** * Domain to be validated */ domainName?: pulumi.Input; /** * Set of domain validation objects which can be used to complete certificate validation. * Can have more than one element, e.g., if SANs are defined. * Only set if `DNS`-validation was used. */ domainValidationOptions?: pulumi.Input[] | undefined>; earlyRenewalDuration?: pulumi.Input; keyAlgorithm?: pulumi.Input; /** * Expiration date and time of the certificate. */ notAfter?: pulumi.Input; /** * Start of the validity period of the certificate. */ notBefore?: pulumi.Input; options?: pulumi.Input; /** * `true` if a Private certificate eligible for managed renewal is within the `earlyRenewalDuration` period. */ pendingRenewal?: pulumi.Input; privateKey?: pulumi.Input; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. */ privateKeyWo?: pulumi.Input; privateKeyWoVersion?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. * * Creating an Amazon issued certificate */ region?: pulumi.Input; /** * Whether the certificate is eligible for managed renewal. */ renewalEligibility?: pulumi.Input; /** * Contains information about the status of ACM's [managed renewal](https://docs.aws.amazon.com/acm/latest/userguide/acm-renewal.html) for the certificate. */ renewalSummaries?: pulumi.Input[] | undefined>; /** * Status of the certificate. */ status?: pulumi.Input; subjectAlternativeNames?: pulumi.Input[] | undefined>; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Source of the certificate. */ type?: pulumi.Input; /** * List of addresses that received a validation email. Only set if `EMAIL` validation was used. */ validationEmails?: pulumi.Input[] | undefined>; validationMethod?: pulumi.Input; validationOptions?: pulumi.Input[] | undefined>; } /** * The set of arguments for constructing a Certificate resource. */ export interface CertificateArgs { certificateAuthorityArn?: pulumi.Input; certificateBody?: pulumi.Input; certificateChain?: pulumi.Input; /** * Domain to be validated */ domainName?: pulumi.Input; earlyRenewalDuration?: pulumi.Input; keyAlgorithm?: pulumi.Input; options?: pulumi.Input; privateKey?: pulumi.Input; /** * **NOTE:** This field is write-only and its value will not be updated in state as part of read operations. */ privateKeyWo?: pulumi.Input; privateKeyWoVersion?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. * * Creating an Amazon issued certificate */ region?: pulumi.Input; subjectAlternativeNames?: pulumi.Input[] | undefined>; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; validationMethod?: pulumi.Input; validationOptions?: pulumi.Input[] | undefined>; } //# sourceMappingURL=certificate.d.ts.map