import * as pulumi from "@pulumi/pulumi"; import { input as inputs, output as outputs } from "../../types"; /** * Create a new CertificateAuthority in a given Project and Location. */ export declare class CertificateAuthority extends pulumi.CustomResource { /** * Get an existing CertificateAuthority resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, opts?: pulumi.CustomResourceOptions): CertificateAuthority; /** * Returns true if the given object is an instance of CertificateAuthority. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is CertificateAuthority; /** * URLs for accessing content published by this CA, such as the CA certificate and CRLs. */ readonly accessUrls: pulumi.Output; /** * A structured description of this CertificateAuthority's CA certificate and its issuers. Ordered as self-to-root. */ readonly caCertificateDescriptions: pulumi.Output; /** * Optional. The CertificateAuthorityPolicy to enforce when issuing Certificates from this CertificateAuthority. */ readonly certificatePolicy: pulumi.Output; /** * Required. Immutable. The config used to create a self-signed X.509 certificate or CSR. */ readonly config: pulumi.Output; /** * The time at which this CertificateAuthority was created. */ readonly createTime: pulumi.Output; /** * The time at which this CertificateAuthority will be deleted, if scheduled for deletion. */ readonly deleteTime: pulumi.Output; /** * Immutable. The name of a Cloud Storage bucket where this CertificateAuthority will publish content, such as the CA certificate and CRLs. This must be a bucket name, without any prefixes (such as `gs://`) or suffixes (such as `.googleapis.com`). For example, to use a bucket named `my-bucket`, you would simply specify `my-bucket`. If not specified, a managed bucket will be created. */ readonly gcsBucket: pulumi.Output; /** * Optional. The IssuingOptions to follow when issuing Certificates from this CertificateAuthority. */ readonly issuingOptions: pulumi.Output; /** * Required. Immutable. Used when issuing certificates for this CertificateAuthority. If this CertificateAuthority is a self-signed CertificateAuthority, this key is also used to sign the self-signed CA certificate. Otherwise, it is used to sign a CSR. */ readonly keySpec: pulumi.Output; /** * Optional. Labels with user-defined metadata. */ readonly labels: pulumi.Output<{ [key: string]: string; }>; /** * Required. The desired lifetime of the CA certificate. Used to create the "not_before_time" and "not_after_time" fields inside an X.509 certificate. */ readonly lifetime: pulumi.Output; /** * The resource name for this CertificateAuthority in the format `projects/*/locations/*/certificateAuthorities/*`. */ readonly name: pulumi.Output; /** * This CertificateAuthority's certificate chain, including the current CertificateAuthority's certificate. Ordered such that the root issuer is the final element (consistent with RFC 5246). For a self-signed CA, this will only list the current CertificateAuthority's certificate. */ readonly pemCaCertificates: pulumi.Output; /** * The State for this CertificateAuthority. */ readonly state: pulumi.Output; /** * Optional. If this is a subordinate CertificateAuthority, this field will be set with the subordinate configuration, which describes its issuers. This may be updated, but this CertificateAuthority must continue to validate. */ readonly subordinateConfig: pulumi.Output; /** * Required. Immutable. The Tier of this CertificateAuthority. */ readonly tier: pulumi.Output; /** * Required. Immutable. The Type of this CertificateAuthority. */ readonly type: pulumi.Output; /** * The time at which this CertificateAuthority was updated. */ readonly updateTime: pulumi.Output; /** * Create a CertificateAuthority resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: CertificateAuthorityArgs, opts?: pulumi.CustomResourceOptions); } /** * The set of arguments for constructing a CertificateAuthority resource. */ export interface CertificateAuthorityArgs { readonly certificateAuthoritiesId: pulumi.Input; /** * Optional. The CertificateAuthorityPolicy to enforce when issuing Certificates from this CertificateAuthority. */ readonly certificatePolicy?: pulumi.Input; /** * Required. Immutable. The config used to create a self-signed X.509 certificate or CSR. */ readonly config?: pulumi.Input; /** * Immutable. The name of a Cloud Storage bucket where this CertificateAuthority will publish content, such as the CA certificate and CRLs. This must be a bucket name, without any prefixes (such as `gs://`) or suffixes (such as `.googleapis.com`). For example, to use a bucket named `my-bucket`, you would simply specify `my-bucket`. If not specified, a managed bucket will be created. */ readonly gcsBucket?: pulumi.Input; /** * Optional. The IssuingOptions to follow when issuing Certificates from this CertificateAuthority. */ readonly issuingOptions?: pulumi.Input; /** * Required. Immutable. Used when issuing certificates for this CertificateAuthority. If this CertificateAuthority is a self-signed CertificateAuthority, this key is also used to sign the self-signed CA certificate. Otherwise, it is used to sign a CSR. */ readonly keySpec?: pulumi.Input; /** * Optional. Labels with user-defined metadata. */ readonly labels?: pulumi.Input<{ [key: string]: pulumi.Input; }>; /** * Required. The desired lifetime of the CA certificate. Used to create the "not_before_time" and "not_after_time" fields inside an X.509 certificate. */ readonly lifetime?: pulumi.Input; readonly locationsId: pulumi.Input; readonly projectsId: pulumi.Input; /** * Optional. If this is a subordinate CertificateAuthority, this field will be set with the subordinate configuration, which describes its issuers. This may be updated, but this CertificateAuthority must continue to validate. */ readonly subordinateConfig?: pulumi.Input; /** * Required. Immutable. The Tier of this CertificateAuthority. */ readonly tier?: pulumi.Input; /** * Required. Immutable. The Type of this CertificateAuthority. */ readonly type?: pulumi.Input; }