import * as pulumi from "@pulumi/pulumi"; import * as inputs from "./types/input"; import * as outputs from "./types/output"; export declare class IdentityKubernetesAuth extends pulumi.CustomResource { /** * Get an existing IdentityKubernetesAuth resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: IdentityKubernetesAuthState, opts?: pulumi.CustomResourceOptions): IdentityKubernetesAuth; /** * Returns true if the given object is an instance of IdentityKubernetesAuth. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is IdentityKubernetesAuth; /** * The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 */ readonly accessTokenMaxTtl: pulumi.Output; /** * The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0 */ readonly accessTokenNumUsesLimit: pulumi.Output; /** * A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address.. */ readonly accessTokenTrustedIps: pulumi.Output; /** * The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 */ readonly accessTokenTtl: pulumi.Output; /** * An optional audience claim that the service account JWT token must have to authenticate with Infisical. */ readonly allowedAudience: pulumi.Output; /** * List of trusted namespaces that service accounts must belong to authenticate with Infisical. */ readonly allowedNamespaces: pulumi.Output; /** * List of trusted service account names that are allowed to authenticate with Infisical. */ readonly allowedServiceAccountNames: pulumi.Output; /** * Select a gateway for private cluster access. If not specified, the Internet Gateway will be used. */ readonly gatewayId: pulumi.Output; /** * The ID of the identity to attach the configuration onto. */ readonly identityId: pulumi.Output; /** * The PEM-encoded CA cert for the Kubernetes API server. This is used by the TLS client for secure communication with the Kubernetes API server. */ readonly kubernetesCaCertificate: pulumi.Output; /** * The host string, host:port pair, or URL to the base of the Kubernetes API server. This can usually be obtained by running `kubectl cluster-info`. */ readonly kubernetesHost: pulumi.Output; /** * A long-lived service account JWT token for Infisical to access the [TokenReview API](https://kubernetes.io/docs/reference/kubernetes-api/authentication-resources/token-review-v1/) to validate other service account JWT tokens submitted by applications/pods. This is the JWT token obtained from step 1.5. */ readonly tokenReviewerJwt: pulumi.Output; /** * Choose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster. */ readonly tokenReviewerMode: pulumi.Output; /** * Create a IdentityKubernetesAuth resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: IdentityKubernetesAuthArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering IdentityKubernetesAuth resources. */ export interface IdentityKubernetesAuthState { /** * The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 */ accessTokenMaxTtl?: pulumi.Input; /** * The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0 */ accessTokenNumUsesLimit?: pulumi.Input; /** * A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address.. */ accessTokenTrustedIps?: pulumi.Input[] | undefined>; /** * The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 */ accessTokenTtl?: pulumi.Input; /** * An optional audience claim that the service account JWT token must have to authenticate with Infisical. */ allowedAudience?: pulumi.Input; /** * List of trusted namespaces that service accounts must belong to authenticate with Infisical. */ allowedNamespaces?: pulumi.Input[] | undefined>; /** * List of trusted service account names that are allowed to authenticate with Infisical. */ allowedServiceAccountNames?: pulumi.Input[] | undefined>; /** * Select a gateway for private cluster access. If not specified, the Internet Gateway will be used. */ gatewayId?: pulumi.Input; /** * The ID of the identity to attach the configuration onto. */ identityId?: pulumi.Input; /** * The PEM-encoded CA cert for the Kubernetes API server. This is used by the TLS client for secure communication with the Kubernetes API server. */ kubernetesCaCertificate?: pulumi.Input; /** * The host string, host:port pair, or URL to the base of the Kubernetes API server. This can usually be obtained by running `kubectl cluster-info`. */ kubernetesHost?: pulumi.Input; /** * A long-lived service account JWT token for Infisical to access the [TokenReview API](https://kubernetes.io/docs/reference/kubernetes-api/authentication-resources/token-review-v1/) to validate other service account JWT tokens submitted by applications/pods. This is the JWT token obtained from step 1.5. */ tokenReviewerJwt?: pulumi.Input; /** * Choose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster. */ tokenReviewerMode?: pulumi.Input; } /** * The set of arguments for constructing a IdentityKubernetesAuth resource. */ export interface IdentityKubernetesAuthArgs { /** * The maximum lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 */ accessTokenMaxTtl?: pulumi.Input; /** * The maximum number of times that an access token can be used; a value of 0 implies infinite number of uses. Default:0 */ accessTokenNumUsesLimit?: pulumi.Input; /** * A list of IPs or CIDR ranges that access tokens can be used from. You can use 0.0.0.0/0, to allow usage from any network address.. */ accessTokenTrustedIps?: pulumi.Input[] | undefined>; /** * The lifetime for an access token in seconds. This value will be referenced at renewal time. Default: 2592000 */ accessTokenTtl?: pulumi.Input; /** * An optional audience claim that the service account JWT token must have to authenticate with Infisical. */ allowedAudience?: pulumi.Input; /** * List of trusted namespaces that service accounts must belong to authenticate with Infisical. */ allowedNamespaces?: pulumi.Input[] | undefined>; /** * List of trusted service account names that are allowed to authenticate with Infisical. */ allowedServiceAccountNames?: pulumi.Input[] | undefined>; /** * Select a gateway for private cluster access. If not specified, the Internet Gateway will be used. */ gatewayId?: pulumi.Input; /** * The ID of the identity to attach the configuration onto. */ identityId: pulumi.Input; /** * The PEM-encoded CA cert for the Kubernetes API server. This is used by the TLS client for secure communication with the Kubernetes API server. */ kubernetesCaCertificate?: pulumi.Input; /** * The host string, host:port pair, or URL to the base of the Kubernetes API server. This can usually be obtained by running `kubectl cluster-info`. */ kubernetesHost?: pulumi.Input; /** * A long-lived service account JWT token for Infisical to access the [TokenReview API](https://kubernetes.io/docs/reference/kubernetes-api/authentication-resources/token-review-v1/) to validate other service account JWT tokens submitted by applications/pods. This is the JWT token obtained from step 1.5. */ tokenReviewerJwt?: pulumi.Input; /** * Choose between Token ('api') or 'gateway' authentication. If using Gateway, the Gateway must be deployed in your Kubernetes cluster. */ tokenReviewerMode?: pulumi.Input; } //# sourceMappingURL=identityKubernetesAuth.d.ts.map