Team
Team describes a Pulumi team. A Pulumi team may have its organization managed by another service, such as GitHub.
Properties
kindenum requiredThe kind of team (e.g., pulumi or GitHub-backed).Values:github— GitHub- TeamKindGitHub is for teams where membership is managed by GitHub.
pulumi— Pulumi- TeamKindPulumi is for teams where membership is managed by Pulumi.
scim— SCIM- TeamKindSCIM is for SCIM provisioned teams. Membership is managed by its IdP.
namestring requiredThe unique identifier name of the team within the organization.displayNamestring requiredThe human-readable display name shown in the UI.descriptionstring requiredA free-form text description of the team’s purpose.- The list of team members.
- ↳
namestring requiredThe user’s display name. - ↳
roleenum requiredThe member’s role within the team.Values:none,member,admin - ↳
githubLoginstring requiredThe user’s login name. - ↳
avatarUrlstring requiredThe URL of the user’s avatar image. - ↳
emailstring optionalThe user’s email address. It is only populated on selected endpoints and is omitted from most responses. Treat it as sensitive information. - The list of stack permissions granted to the team.
- ↳
projectNamestring requiredThe project containing the stack. - ↳
stackNamestring requiredThe stack within the project. - ↳
permissionenum requiredThe permission level the team has on this stack (e.g., read, write, admin). On editStackPermission, set to “none” to remove the stack from the team. addStackPermission ignores “none” — including an omitted permission, which reads as “none” — and stores nothing: adding is how a grant is created, and removeStack is how one is revoked.Values:0— None- StackPermissionNone provides no access.
101— Read- StackPermissionRead provides read-only access, including the ability to decrypt encrypted configuration secrets stored in the service.
102— Write- StackPermissionWrite provides read/write access to a stack.
103— Admin- StackPermissionAdmin provides admin-level access to the stack. For example,
being able to run
pulumi destroyor delete the stack. 104— Creator- StackPermissionCreator identifies the user who created the stack. It confers the same access as StackPermissionAdmin.
- ↳
permissionSetNamestring optionalDisplay name of the permission set for this stack, when available. Enables read-only entity access UI without requiring RoleRead. - The list of environment settings for the team.
- ↳
projectNamestring requiredThe project containing the environment. - ↳
envNamestring requiredThe environment within the project. - ↳
permissionenum requiredThe permission level the team has on this environment. On editEnvironmentPermission, set to “none” to remove the environment from the team. addEnvironmentPermission ignores “none” and stores nothing: adding is how a grant is created, and removeEnvironment is how one is revoked.Values:none,read,open,write,admin - ↳
maxOpenDurationstring optionalThe maximum duration an environment session can remain open, as a Go duration string (e.g. “1h30m”). - ↳
permissionSetNamestring optionalDisplay name of the permission set for this environment, when available. Enables read-only entity access UI without requiring RoleRead. - The list of account permissions granted to the team.
- ↳
accountNamestring requiredThe Insights account name. - ↳
permissionenum requiredThe permission level the team has on this Insights account.Values:0— None- InsightsAccountPermissionNone provides no access.
1— Read- InsightsAccountPermissionRead provides read-only access.
2— Write- InsightsAccountPermissionWrite provides read/write access to an account.
3— Admin- InsightsAccountPermissionAdmin provides admin-level access to the account.
- ↳
permissionSetNamestring optionalDisplay name of the permission set for this account, when available. Enables read-only entity access UI without requiring RoleRead. listMembersErrorstring optionalListMembersError is the error message if an error was encountered whilst trying to contact the team’s backend (eg. GitHub). The UI will only show this error if it is non-nil and if Members itself is an empty slice.userRoleenum optionalUserRole is the calling user’s role on the given team.Values:none,member,adminroleIdsarray[string] optionalRoleIDs are the IDs of the FGA roles assigned to the team, if any. Currently only one role per team is supported.