Skip to main content
Pulumi logo Pulumi logo
  1. Docs
  2. pulumi env setup azure | CLI commands

pulumi env setup azure | CLI commands

Generated for Pulumi CLI v3.262.0.

    [EXPERIMENTAL] Set up Azure OIDC integration for Pulumi ESC

    Synopsis

    [EXPERIMENTAL] Set up Azure OIDC integration for Pulumi ESC

    Creates, in your Azure tenant:

    • an app registration trusting Pulumi Cloud as an OIDC identity provider
    • a federated identity credential and a service principal
    • a role assignment on each selected subscription

    You are asked how to authenticate: with the Azure credentials you already have (from az login or environment variables), or by signing in through your browser. Both span the whole tenant.

    Each selected subscription gets its own environment, pinning that subscription.

    Examples: pulumi env setup azure –policy Contributor pulumi env setup azure –policy Reader –subscription –yes

    pulumi env setup azure [flags]
    

    Options

          --browser                     force browser sign-in instead of using existing credentials
      -h, --help                        help for azure
          --org string                  the Pulumi organization to configure OIDC for
          --policy string               the role assigned per subscription: Contributor (required for Deployments), Reader (required for Insights), or any other role definition ID; prompted for when omitted
          --project string              the ESC project that per-subscription environments are created in (default "azure-login")
          --subscription subscription   an Azure subscription to set up (repeatable; prompted for when omitted)
          --tenant string               the Azure tenant to configure, which only its own subscriptions are visible through (prompted for when omitted)
          --yes                         skip all confirmation prompts
    

    Options inherited from parent commands

          --color string                 Colorize output. Choices are: always, never, raw, auto (default "auto")
      -C, --cwd string                   Run pulumi as if it had been started in another directory
          --disable-integrity-checking   Disable integrity checking of checkpoint files
      -e, --emoji                        Enable emojis in the output
          --env string                   The name of the environment to operate on.
      -Q, --fully-qualify-stack-names    Show fully-qualified stack names
          --logflow                      Flow log settings to child processes (like plugins)
          --logtostderr                  Log to stderr instead of to files
          --memprofilerate int           Enable more precise (and expensive) memory allocation profiles by setting runtime.MemProfileRate
          --non-interactive              Disable interactive mode for all commands
          --otel-traces string           Export OpenTelemetry traces to the specified endpoint. Use file:// for local JSON files, grpc:// or https:// for remote collectors
          --profiling string             Emit CPU and memory profiles and an execution trace to '[filename].[pid].{cpu,mem,trace}', respectively
          --tracing file:                Emit tracing to the specified endpoint. Use the file: scheme to write tracing data to a local file
      -v, --verbose int                  Enable verbose logging (e.g., v=3); anything >3 is very verbose
    

    SEE ALSO

      The infrastructure as code platform for any cloud.