import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../../types/input"; import * as outputs from "../../types/output"; import * as enums from "../../types/enums"; /** * Create a new CertificateAuthority in a given Project and Location. * Auto-naming is currently not supported for this resource. */ export declare class CertificateAuthority extends pulumi.CustomResource { /** * Get an existing CertificateAuthority resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, opts?: pulumi.CustomResourceOptions): CertificateAuthority; /** * Returns true if the given object is an instance of CertificateAuthority. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is CertificateAuthority; /** * URLs for accessing content published by this CA, such as the CA certificate and CRLs. */ readonly accessUrls: pulumi.Output; /** * A structured description of this CertificateAuthority's CA certificate and its issuers. Ordered as self-to-root. */ readonly caCertificateDescriptions: pulumi.Output; readonly caPoolId: pulumi.Output; /** * Required. It must be unique within a location and match the regular expression `[a-zA-Z0-9_-]{1,63}` */ readonly certificateAuthorityId: pulumi.Output; /** * Immutable. The config used to create a self-signed X.509 certificate or CSR. */ readonly config: pulumi.Output; /** * The time at which this CertificateAuthority was created. */ readonly createTime: pulumi.Output; /** * The time at which this CertificateAuthority was soft deleted, if it is in the DELETED state. */ readonly deleteTime: pulumi.Output; /** * The time at which this CertificateAuthority will be permanently purged, if it is in the DELETED state. */ readonly expireTime: pulumi.Output; /** * Immutable. The name of a Cloud Storage bucket where this CertificateAuthority will publish content, such as the CA certificate and CRLs. This must be a bucket name, without any prefixes (such as `gs://`) or suffixes (such as `.googleapis.com`). For example, to use a bucket named `my-bucket`, you would simply specify `my-bucket`. If not specified, a managed bucket will be created. */ readonly gcsBucket: pulumi.Output; /** * Immutable. Used when issuing certificates for this CertificateAuthority. If this CertificateAuthority is a self-signed CertificateAuthority, this key is also used to sign the self-signed CA certificate. Otherwise, it is used to sign a CSR. */ readonly keySpec: pulumi.Output; /** * Optional. Labels with user-defined metadata. */ readonly labels: pulumi.Output<{ [key: string]: string; }>; /** * Immutable. The desired lifetime of the CA certificate. Used to create the "not_before_time" and "not_after_time" fields inside an X.509 certificate. */ readonly lifetime: pulumi.Output; readonly location: pulumi.Output; /** * The resource name for this CertificateAuthority in the format `projects/*/locations/*/caPools/*/certificateAuthorities/*`. */ readonly name: pulumi.Output; /** * This CertificateAuthority's certificate chain, including the current CertificateAuthority's certificate. Ordered such that the root issuer is the final element (consistent with RFC 5246). For a self-signed CA, this will only list the current CertificateAuthority's certificate. */ readonly pemCaCertificates: pulumi.Output; readonly project: pulumi.Output; /** * Optional. An ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000). */ readonly requestId: pulumi.Output; /** * The State for this CertificateAuthority. */ readonly state: pulumi.Output; /** * Optional. If this is a subordinate CertificateAuthority, this field will be set with the subordinate configuration, which describes its issuers. This may be updated, but this CertificateAuthority must continue to validate. */ readonly subordinateConfig: pulumi.Output; /** * The CaPool.Tier of the CaPool that includes this CertificateAuthority. */ readonly tier: pulumi.Output; /** * Immutable. The Type of this CertificateAuthority. */ readonly type: pulumi.Output; /** * The time at which this CertificateAuthority was last updated. */ readonly updateTime: pulumi.Output; /** * Create a CertificateAuthority resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: CertificateAuthorityArgs, opts?: pulumi.CustomResourceOptions); } /** * The set of arguments for constructing a CertificateAuthority resource. */ export interface CertificateAuthorityArgs { caPoolId: pulumi.Input; /** * Required. It must be unique within a location and match the regular expression `[a-zA-Z0-9_-]{1,63}` */ certificateAuthorityId: pulumi.Input; /** * Immutable. The config used to create a self-signed X.509 certificate or CSR. */ config: pulumi.Input; /** * Immutable. The name of a Cloud Storage bucket where this CertificateAuthority will publish content, such as the CA certificate and CRLs. This must be a bucket name, without any prefixes (such as `gs://`) or suffixes (such as `.googleapis.com`). For example, to use a bucket named `my-bucket`, you would simply specify `my-bucket`. If not specified, a managed bucket will be created. */ gcsBucket?: pulumi.Input; /** * Immutable. Used when issuing certificates for this CertificateAuthority. If this CertificateAuthority is a self-signed CertificateAuthority, this key is also used to sign the self-signed CA certificate. Otherwise, it is used to sign a CSR. */ keySpec: pulumi.Input; /** * Optional. Labels with user-defined metadata. */ labels?: pulumi.Input<{ [key: string]: pulumi.Input; }>; /** * Immutable. The desired lifetime of the CA certificate. Used to create the "not_before_time" and "not_after_time" fields inside an X.509 certificate. */ lifetime: pulumi.Input; location?: pulumi.Input; project?: pulumi.Input; /** * Optional. An ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000). */ requestId?: pulumi.Input; /** * Optional. If this is a subordinate CertificateAuthority, this field will be set with the subordinate configuration, which describes its issuers. This may be updated, but this CertificateAuthority must continue to validate. */ subordinateConfig?: pulumi.Input; /** * Immutable. The Type of this CertificateAuthority. */ type: pulumi.Input; }