published on Friday, Sep 25, 2026 by Pulumiverse
published on Friday, Sep 25, 2026 by Pulumiverse
Create Certificate Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new Certificate(name: string, args: CertificateArgs, opts?: CustomResourceOptions);@overload
def Certificate(resource_name: str,
args: CertificateArgs,
opts: Optional[ResourceOptions] = None)
@overload
def Certificate(resource_name: str,
opts: Optional[ResourceOptions] = None,
account_key_pem: Optional[str] = None,
cert_timeout: Optional[int] = None,
certificate_p12_password: Optional[str] = None,
certificate_request_pem: Optional[str] = None,
common_name: Optional[str] = None,
deactivate_authorizations: Optional[bool] = None,
disable_authoritative_propagation: Optional[bool] = None,
dns_challenges: Optional[Sequence[CertificateDnsChallengeArgs]] = None,
http_challenge: Optional[CertificateHttpChallengeArgs] = None,
http_memcached_challenge: Optional[CertificateHttpMemcachedChallengeArgs] = None,
http_s3_challenge: Optional[CertificateHttpS3ChallengeArgs] = None,
http_webroot_challenge: Optional[CertificateHttpWebrootChallengeArgs] = None,
key_type: Optional[str] = None,
min_days_dynamic: Optional[bool] = None,
min_days_remaining: Optional[int] = None,
must_staple: Optional[bool] = None,
pre_check_delay: Optional[int] = None,
preferred_chain: Optional[str] = None,
profile: Optional[str] = None,
propagation_wait: Optional[int] = None,
recursive_nameservers: Optional[Sequence[str]] = None,
renewal_info_ignore_retry_after: Optional[bool] = None,
renewal_info_max_sleep: Optional[int] = None,
revoke_certificate_on_destroy: Optional[bool] = None,
revoke_certificate_reason: Optional[str] = None,
subject_alternative_names: Optional[Sequence[str]] = None,
tls_challenge: Optional[CertificateTlsChallengeArgs] = None,
use_renewal_info: Optional[bool] = None,
validity_days: Optional[int] = None)func NewCertificate(ctx *Context, name string, args CertificateArgs, opts ...ResourceOption) (*Certificate, error)public Certificate(string name, CertificateArgs args, CustomResourceOptions? opts = null)
public Certificate(String name, CertificateArgs args)
public Certificate(String name, CertificateArgs args, CustomResourceOptions options)
type: acme:Certificate
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "acme_certificate" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args CertificateArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args CertificateArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args CertificateArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args CertificateArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args CertificateArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var certificateResource = new Acme.Certificate("certificateResource", new()
{
AccountKeyPem = "string",
CertTimeout = 0,
CertificateP12Password = "string",
CertificateRequestPem = "string",
CommonName = "string",
DeactivateAuthorizations = false,
DisableAuthoritativePropagation = false,
DnsChallenges = new[]
{
new Acme.Inputs.CertificateDnsChallengeArgs
{
Provider = "string",
Config =
{
{ "string", "string" },
},
MatchDomains = new[]
{
"string",
},
},
},
HttpChallenge = new Acme.Inputs.CertificateHttpChallengeArgs
{
Port = 0,
ProxyHeader = "string",
},
HttpMemcachedChallenge = new Acme.Inputs.CertificateHttpMemcachedChallengeArgs
{
Hosts = new[]
{
"string",
},
},
HttpS3Challenge = new Acme.Inputs.CertificateHttpS3ChallengeArgs
{
S3Bucket = "string",
},
HttpWebrootChallenge = new Acme.Inputs.CertificateHttpWebrootChallengeArgs
{
Directory = "string",
},
KeyType = "string",
MinDaysDynamic = false,
MinDaysRemaining = 0,
MustStaple = false,
PreCheckDelay = 0,
PreferredChain = "string",
Profile = "string",
PropagationWait = 0,
RecursiveNameservers = new[]
{
"string",
},
RenewalInfoIgnoreRetryAfter = false,
RenewalInfoMaxSleep = 0,
RevokeCertificateOnDestroy = false,
RevokeCertificateReason = "string",
SubjectAlternativeNames = new[]
{
"string",
},
TlsChallenge = new Acme.Inputs.CertificateTlsChallengeArgs
{
Port = 0,
},
UseRenewalInfo = false,
ValidityDays = 0,
});
example, err := acme.NewCertificate(ctx, "certificateResource", &acme.CertificateArgs{
AccountKeyPem: pulumi.String("string"),
CertTimeout: pulumi.Int(0),
CertificateP12Password: pulumi.String("string"),
CertificateRequestPem: pulumi.String("string"),
CommonName: pulumi.String("string"),
DeactivateAuthorizations: pulumi.Bool(false),
DisableAuthoritativePropagation: pulumi.Bool(false),
DnsChallenges: acme.CertificateDnsChallengeArray{
&acme.CertificateDnsChallengeArgs{
Provider: pulumi.String("string"),
Config: pulumi.StringMap{
"string": pulumi.String("string"),
},
MatchDomains: pulumi.StringArray{
pulumi.String("string"),
},
},
},
HttpChallenge: &acme.CertificateHttpChallengeArgs{
Port: pulumi.Int(0),
ProxyHeader: pulumi.String("string"),
},
HttpMemcachedChallenge: &acme.CertificateHttpMemcachedChallengeArgs{
Hosts: pulumi.StringArray{
pulumi.String("string"),
},
},
HttpS3Challenge: &acme.CertificateHttpS3ChallengeArgs{
S3Bucket: pulumi.String("string"),
},
HttpWebrootChallenge: &acme.CertificateHttpWebrootChallengeArgs{
Directory: pulumi.String("string"),
},
KeyType: pulumi.String("string"),
MinDaysDynamic: pulumi.Bool(false),
MinDaysRemaining: pulumi.Int(0),
MustStaple: pulumi.Bool(false),
PreCheckDelay: pulumi.Int(0),
PreferredChain: pulumi.String("string"),
Profile: pulumi.String("string"),
PropagationWait: pulumi.Int(0),
RecursiveNameservers: pulumi.StringArray{
pulumi.String("string"),
},
RenewalInfoIgnoreRetryAfter: pulumi.Bool(false),
RenewalInfoMaxSleep: pulumi.Int(0),
RevokeCertificateOnDestroy: pulumi.Bool(false),
RevokeCertificateReason: pulumi.String("string"),
SubjectAlternativeNames: pulumi.StringArray{
pulumi.String("string"),
},
TlsChallenge: &acme.CertificateTlsChallengeArgs{
Port: pulumi.Int(0),
},
UseRenewalInfo: pulumi.Bool(false),
ValidityDays: pulumi.Int(0),
})
resource "acme_certificate" "certificateResource" {
lifecycle {
create_before_destroy = true
}
account_key_pem = "string"
cert_timeout = 0
certificate_p12_password = "string"
certificate_request_pem = "string"
common_name = "string"
deactivate_authorizations = false
disable_authoritative_propagation = false
dns_challenges {
provider = "string"
config = {
"string" = "string"
}
match_domains = ["string"]
}
http_challenge = {
port = 0
proxy_header = "string"
}
http_memcached_challenge = {
hosts = ["string"]
}
http_s3_challenge = {
s3_bucket = "string"
}
http_webroot_challenge = {
directory = "string"
}
key_type = "string"
min_days_dynamic = false
min_days_remaining = 0
must_staple = false
pre_check_delay = 0
preferred_chain = "string"
profile = "string"
propagation_wait = 0
recursive_nameservers = ["string"]
renewal_info_ignore_retry_after = false
renewal_info_max_sleep = 0
revoke_certificate_on_destroy = false
revoke_certificate_reason = "string"
subject_alternative_names = ["string"]
tls_challenge = {
port = 0
}
use_renewal_info = false
validity_days = 0
}
var certificateResource = new Certificate("certificateResource", CertificateArgs.builder()
.accountKeyPem("string")
.certTimeout(0)
.certificateP12Password("string")
.certificateRequestPem("string")
.commonName("string")
.deactivateAuthorizations(false)
.disableAuthoritativePropagation(false)
.dnsChallenges(CertificateDnsChallengeArgs.builder()
.provider("string")
.config(Map.of("string", "string"))
.matchDomains("string")
.build())
.httpChallenge(CertificateHttpChallengeArgs.builder()
.port(0)
.proxyHeader("string")
.build())
.httpMemcachedChallenge(CertificateHttpMemcachedChallengeArgs.builder()
.hosts("string")
.build())
.httpS3Challenge(CertificateHttpS3ChallengeArgs.builder()
.s3Bucket("string")
.build())
.httpWebrootChallenge(CertificateHttpWebrootChallengeArgs.builder()
.directory("string")
.build())
.keyType("string")
.minDaysDynamic(false)
.minDaysRemaining(0)
.mustStaple(false)
.preCheckDelay(0)
.preferredChain("string")
.profile("string")
.propagationWait(0)
.recursiveNameservers("string")
.renewalInfoIgnoreRetryAfter(false)
.renewalInfoMaxSleep(0)
.revokeCertificateOnDestroy(false)
.revokeCertificateReason("string")
.subjectAlternativeNames("string")
.tlsChallenge(CertificateTlsChallengeArgs.builder()
.port(0)
.build())
.useRenewalInfo(false)
.validityDays(0)
.build());
certificate_resource = acme.Certificate("certificateResource",
account_key_pem="string",
cert_timeout=0,
certificate_p12_password="string",
certificate_request_pem="string",
common_name="string",
deactivate_authorizations=False,
disable_authoritative_propagation=False,
dns_challenges=[{
"provider": "string",
"config": {
"string": "string",
},
"match_domains": ["string"],
}],
http_challenge={
"port": 0,
"proxy_header": "string",
},
http_memcached_challenge={
"hosts": ["string"],
},
http_s3_challenge={
"s3_bucket": "string",
},
http_webroot_challenge={
"directory": "string",
},
key_type="string",
min_days_dynamic=False,
min_days_remaining=0,
must_staple=False,
pre_check_delay=0,
preferred_chain="string",
profile="string",
propagation_wait=0,
recursive_nameservers=["string"],
renewal_info_ignore_retry_after=False,
renewal_info_max_sleep=0,
revoke_certificate_on_destroy=False,
revoke_certificate_reason="string",
subject_alternative_names=["string"],
tls_challenge={
"port": 0,
},
use_renewal_info=False,
validity_days=0)
const certificateResource = new acme.Certificate("certificateResource", {
accountKeyPem: "string",
certTimeout: 0,
certificateP12Password: "string",
certificateRequestPem: "string",
commonName: "string",
deactivateAuthorizations: false,
disableAuthoritativePropagation: false,
dnsChallenges: [{
provider: "string",
config: {
string: "string",
},
matchDomains: ["string"],
}],
httpChallenge: {
port: 0,
proxyHeader: "string",
},
httpMemcachedChallenge: {
hosts: ["string"],
},
httpS3Challenge: {
s3Bucket: "string",
},
httpWebrootChallenge: {
directory: "string",
},
keyType: "string",
minDaysDynamic: false,
minDaysRemaining: 0,
mustStaple: false,
preCheckDelay: 0,
preferredChain: "string",
profile: "string",
propagationWait: 0,
recursiveNameservers: ["string"],
renewalInfoIgnoreRetryAfter: false,
renewalInfoMaxSleep: 0,
revokeCertificateOnDestroy: false,
revokeCertificateReason: "string",
subjectAlternativeNames: ["string"],
tlsChallenge: {
port: 0,
},
useRenewalInfo: false,
validityDays: 0,
});
type: acme:Certificate
properties:
accountKeyPem: string
certTimeout: 0
certificateP12Password: string
certificateRequestPem: string
commonName: string
deactivateAuthorizations: false
disableAuthoritativePropagation: false
dnsChallenges:
- config:
string: string
matchDomains:
- string
provider: string
httpChallenge:
port: 0
proxyHeader: string
httpMemcachedChallenge:
hosts:
- string
httpS3Challenge:
s3Bucket: string
httpWebrootChallenge:
directory: string
keyType: string
minDaysDynamic: false
minDaysRemaining: 0
mustStaple: false
preCheckDelay: 0
preferredChain: string
profile: string
propagationWait: 0
recursiveNameservers:
- string
renewalInfoIgnoreRetryAfter: false
renewalInfoMaxSleep: 0
revokeCertificateOnDestroy: false
revokeCertificateReason: string
subjectAlternativeNames:
- string
tlsChallenge:
port: 0
useRenewalInfo: false
validityDays: 0
Certificate Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The Certificate resource accepts the following input properties:
- Account
Key stringPem - Cert
Timeout int - Certificate
P12Password string - Certificate
Request stringPem - Common
Name string - bool
- bool
- Dns
Challenges List<Pulumiverse.Acme. Inputs. Certificate Dns Challenge> - Http
Challenge Pulumiverse.Acme. Inputs. Certificate Http Challenge - Http
Memcached Pulumiverse.Challenge Acme. Inputs. Certificate Http Memcached Challenge - Http
S3Challenge Pulumiverse.Acme. Inputs. Certificate Http S3Challenge - Http
Webroot Pulumiverse.Challenge Acme. Inputs. Certificate Http Webroot Challenge - Key
Type string - Min
Days boolDynamic - Min
Days intRemaining - Must
Staple bool - Pre
Check intDelay - Preferred
Chain string - Profile string
- Propagation
Wait int - Recursive
Nameservers List<string> - Renewal
Info boolIgnore Retry After - Renewal
Info intMax Sleep - Revoke
Certificate boolOn Destroy - Revoke
Certificate stringReason - Subject
Alternative List<string>Names - Tls
Challenge Pulumiverse.Acme. Inputs. Certificate Tls Challenge - Use
Renewal boolInfo - Validity
Days int
- Account
Key stringPem - Cert
Timeout int - Certificate
P12Password string - Certificate
Request stringPem - Common
Name string - bool
- bool
- Dns
Challenges []CertificateDns Challenge Args - Http
Challenge CertificateHttp Challenge Args - Http
Memcached CertificateChallenge Http Memcached Challenge Args - Http
S3Challenge CertificateHttp S3Challenge Args - Http
Webroot CertificateChallenge Http Webroot Challenge Args - Key
Type string - Min
Days boolDynamic - Min
Days intRemaining - Must
Staple bool - Pre
Check intDelay - Preferred
Chain string - Profile string
- Propagation
Wait int - Recursive
Nameservers []string - Renewal
Info boolIgnore Retry After - Renewal
Info intMax Sleep - Revoke
Certificate boolOn Destroy - Revoke
Certificate stringReason - Subject
Alternative []stringNames - Tls
Challenge CertificateTls Challenge Args - Use
Renewal boolInfo - Validity
Days int
- account_
key_ stringpem - cert_
timeout number - certificate_
p12_ stringpassword - certificate_
request_ stringpem - common_
name string - bool
- bool
- dns_
challenges list(object) - http_
challenge object - http_
memcached_ objectchallenge - http_
s3_ objectchallenge - http_
webroot_ objectchallenge - key_
type string - min_
days_ booldynamic - min_
days_ numberremaining - must_
staple bool - pre_
check_ numberdelay - preferred_
chain string - profile string
- propagation_
wait number - recursive_
nameservers list(string) - renewal_
info_ boolignore_ retry_ after - renewal_
info_ numbermax_ sleep - revoke_
certificate_ boolon_ destroy - revoke_
certificate_ stringreason - subject_
alternative_ list(string)names - tls_
challenge object - use_
renewal_ boolinfo - validity_
days number
- account
Key StringPem - cert
Timeout Integer - certificate
P12Password String - certificate
Request StringPem - common
Name String - Boolean
- Boolean
- dns
Challenges List<CertificateDns Challenge> - http
Challenge CertificateHttp Challenge - http
Memcached CertificateChallenge Http Memcached Challenge - http
S3Challenge CertificateHttp S3Challenge - http
Webroot CertificateChallenge Http Webroot Challenge - key
Type String - min
Days BooleanDynamic - min
Days IntegerRemaining - must
Staple Boolean - pre
Check IntegerDelay - preferred
Chain String - profile String
- propagation
Wait Integer - recursive
Nameservers List<String> - renewal
Info BooleanIgnore Retry After - renewal
Info IntegerMax Sleep - revoke
Certificate BooleanOn Destroy - revoke
Certificate StringReason - subject
Alternative List<String>Names - tls
Challenge CertificateTls Challenge - use
Renewal BooleanInfo - validity
Days Integer
- account
Key stringPem - cert
Timeout number - certificate
P12Password string - certificate
Request stringPem - common
Name string - boolean
- boolean
- dns
Challenges CertificateDns Challenge[] - http
Challenge CertificateHttp Challenge - http
Memcached CertificateChallenge Http Memcached Challenge - http
S3Challenge CertificateHttp S3Challenge - http
Webroot CertificateChallenge Http Webroot Challenge - key
Type string - min
Days booleanDynamic - min
Days numberRemaining - must
Staple boolean - pre
Check numberDelay - preferred
Chain string - profile string
- propagation
Wait number - recursive
Nameservers string[] - renewal
Info booleanIgnore Retry After - renewal
Info numberMax Sleep - revoke
Certificate booleanOn Destroy - revoke
Certificate stringReason - subject
Alternative string[]Names - tls
Challenge CertificateTls Challenge - use
Renewal booleanInfo - validity
Days number
- account_
key_ strpem - cert_
timeout int - certificate_
p12_ strpassword - certificate_
request_ strpem - common_
name str - bool
- bool
- dns_
challenges Sequence[CertificateDns Challenge Args] - http_
challenge CertificateHttp Challenge Args - http_
memcached_ Certificatechallenge Http Memcached Challenge Args - http_
s3_ Certificatechallenge Http S3Challenge Args - http_
webroot_ Certificatechallenge Http Webroot Challenge Args - key_
type str - min_
days_ booldynamic - min_
days_ intremaining - must_
staple bool - pre_
check_ intdelay - preferred_
chain str - profile str
- propagation_
wait int - recursive_
nameservers Sequence[str] - renewal_
info_ boolignore_ retry_ after - renewal_
info_ intmax_ sleep - revoke_
certificate_ boolon_ destroy - revoke_
certificate_ strreason - subject_
alternative_ Sequence[str]names - tls_
challenge CertificateTls Challenge Args - use_
renewal_ boolinfo - validity_
days int
- account
Key StringPem - cert
Timeout Number - certificate
P12Password String - certificate
Request StringPem - common
Name String - Boolean
- Boolean
- dns
Challenges List<Property Map> - http
Challenge Property Map - http
Memcached Property MapChallenge - http
S3Challenge Property Map - http
Webroot Property MapChallenge - key
Type String - min
Days BooleanDynamic - min
Days NumberRemaining - must
Staple Boolean - pre
Check NumberDelay - preferred
Chain String - profile String
- propagation
Wait Number - recursive
Nameservers List<String> - renewal
Info BooleanIgnore Retry After - renewal
Info NumberMax Sleep - revoke
Certificate BooleanOn Destroy - revoke
Certificate StringReason - subject
Alternative List<String>Names - tls
Challenge Property Map - use
Renewal BooleanInfo - validity
Days Number
Outputs
All input properties are implicitly available as output properties. Additionally, the Certificate resource produces the following output properties:
- Certificate
Domain string - Certificate
Not stringAfter - Certificate
Not stringBefore - Certificate
P12 string - Certificate
Pem string - Certificate
Serial string - Certificate
Url string - Id string
- The provider-assigned unique ID for this managed resource.
- Issuer
Pem string - Private
Key stringPem - Renewal
Info stringExplanation Url - Renewal
Info stringRetry After - Renewal
Info stringWindow End - Renewal
Info stringWindow Selected - Renewal
Info stringWindow Start
- Certificate
Domain string - Certificate
Not stringAfter - Certificate
Not stringBefore - Certificate
P12 string - Certificate
Pem string - Certificate
Serial string - Certificate
Url string - Id string
- The provider-assigned unique ID for this managed resource.
- Issuer
Pem string - Private
Key stringPem - Renewal
Info stringExplanation Url - Renewal
Info stringRetry After - Renewal
Info stringWindow End - Renewal
Info stringWindow Selected - Renewal
Info stringWindow Start
- certificate_
domain string - certificate_
not_ stringafter - certificate_
not_ stringbefore - certificate_
p12 string - certificate_
pem string - certificate_
serial string - certificate_
url string - id string
- The provider-assigned unique ID for this managed resource.
- issuer_
pem string - private_
key_ stringpem - renewal_
info_ stringexplanation_ url - renewal_
info_ stringretry_ after - renewal_
info_ stringwindow_ end - renewal_
info_ stringwindow_ selected - renewal_
info_ stringwindow_ start
- certificate
Domain String - certificate
Not StringAfter - certificate
Not StringBefore - certificate
P12 String - certificate
Pem String - certificate
Serial String - certificate
Url String - id String
- The provider-assigned unique ID for this managed resource.
- issuer
Pem String - private
Key StringPem - renewal
Info StringExplanation Url - renewal
Info StringRetry After - renewal
Info StringWindow End - renewal
Info StringWindow Selected - renewal
Info StringWindow Start
- certificate
Domain string - certificate
Not stringAfter - certificate
Not stringBefore - certificate
P12 string - certificate
Pem string - certificate
Serial string - certificate
Url string - id string
- The provider-assigned unique ID for this managed resource.
- issuer
Pem string - private
Key stringPem - renewal
Info stringExplanation Url - renewal
Info stringRetry After - renewal
Info stringWindow End - renewal
Info stringWindow Selected - renewal
Info stringWindow Start
- certificate_
domain str - certificate_
not_ strafter - certificate_
not_ strbefore - certificate_
p12 str - certificate_
pem str - certificate_
serial str - certificate_
url str - id str
- The provider-assigned unique ID for this managed resource.
- issuer_
pem str - private_
key_ strpem - renewal_
info_ strexplanation_ url - renewal_
info_ strretry_ after - renewal_
info_ strwindow_ end - renewal_
info_ strwindow_ selected - renewal_
info_ strwindow_ start
- certificate
Domain String - certificate
Not StringAfter - certificate
Not StringBefore - certificate
P12 String - certificate
Pem String - certificate
Serial String - certificate
Url String - id String
- The provider-assigned unique ID for this managed resource.
- issuer
Pem String - private
Key StringPem - renewal
Info StringExplanation Url - renewal
Info StringRetry After - renewal
Info StringWindow End - renewal
Info StringWindow Selected - renewal
Info StringWindow Start
Look up Existing Certificate Resource
Get an existing Certificate resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: CertificateState, opts?: CustomResourceOptions): Certificate@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
account_key_pem: Optional[str] = None,
cert_timeout: Optional[int] = None,
certificate_domain: Optional[str] = None,
certificate_not_after: Optional[str] = None,
certificate_not_before: Optional[str] = None,
certificate_p12: Optional[str] = None,
certificate_p12_password: Optional[str] = None,
certificate_pem: Optional[str] = None,
certificate_request_pem: Optional[str] = None,
certificate_serial: Optional[str] = None,
certificate_url: Optional[str] = None,
common_name: Optional[str] = None,
deactivate_authorizations: Optional[bool] = None,
disable_authoritative_propagation: Optional[bool] = None,
dns_challenges: Optional[Sequence[CertificateDnsChallengeArgs]] = None,
http_challenge: Optional[CertificateHttpChallengeArgs] = None,
http_memcached_challenge: Optional[CertificateHttpMemcachedChallengeArgs] = None,
http_s3_challenge: Optional[CertificateHttpS3ChallengeArgs] = None,
http_webroot_challenge: Optional[CertificateHttpWebrootChallengeArgs] = None,
issuer_pem: Optional[str] = None,
key_type: Optional[str] = None,
min_days_dynamic: Optional[bool] = None,
min_days_remaining: Optional[int] = None,
must_staple: Optional[bool] = None,
pre_check_delay: Optional[int] = None,
preferred_chain: Optional[str] = None,
private_key_pem: Optional[str] = None,
profile: Optional[str] = None,
propagation_wait: Optional[int] = None,
recursive_nameservers: Optional[Sequence[str]] = None,
renewal_info_explanation_url: Optional[str] = None,
renewal_info_ignore_retry_after: Optional[bool] = None,
renewal_info_max_sleep: Optional[int] = None,
renewal_info_retry_after: Optional[str] = None,
renewal_info_window_end: Optional[str] = None,
renewal_info_window_selected: Optional[str] = None,
renewal_info_window_start: Optional[str] = None,
revoke_certificate_on_destroy: Optional[bool] = None,
revoke_certificate_reason: Optional[str] = None,
subject_alternative_names: Optional[Sequence[str]] = None,
tls_challenge: Optional[CertificateTlsChallengeArgs] = None,
use_renewal_info: Optional[bool] = None,
validity_days: Optional[int] = None) -> Certificatefunc GetCertificate(ctx *Context, name string, id IDInput, state *CertificateState, opts ...ResourceOption) (*Certificate, error)public static Certificate Get(string name, Input<string> id, CertificateState? state, CustomResourceOptions? opts = null)public static Certificate get(String name, Output<String> id, CertificateState state, CustomResourceOptions options)resources: _: type: acme:Certificate get: id: ${id}import {
to = acme_certificate.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Account
Key stringPem - Cert
Timeout int - Certificate
Domain string - Certificate
Not stringAfter - Certificate
Not stringBefore - Certificate
P12 string - Certificate
P12Password string - Certificate
Pem string - Certificate
Request stringPem - Certificate
Serial string - Certificate
Url string - Common
Name string - bool
- bool
- Dns
Challenges List<Pulumiverse.Acme. Inputs. Certificate Dns Challenge> - Http
Challenge Pulumiverse.Acme. Inputs. Certificate Http Challenge - Http
Memcached Pulumiverse.Challenge Acme. Inputs. Certificate Http Memcached Challenge - Http
S3Challenge Pulumiverse.Acme. Inputs. Certificate Http S3Challenge - Http
Webroot Pulumiverse.Challenge Acme. Inputs. Certificate Http Webroot Challenge - Issuer
Pem string - Key
Type string - Min
Days boolDynamic - Min
Days intRemaining - Must
Staple bool - Pre
Check intDelay - Preferred
Chain string - Private
Key stringPem - Profile string
- Propagation
Wait int - Recursive
Nameservers List<string> - Renewal
Info stringExplanation Url - Renewal
Info boolIgnore Retry After - Renewal
Info intMax Sleep - Renewal
Info stringRetry After - Renewal
Info stringWindow End - Renewal
Info stringWindow Selected - Renewal
Info stringWindow Start - Revoke
Certificate boolOn Destroy - Revoke
Certificate stringReason - Subject
Alternative List<string>Names - Tls
Challenge Pulumiverse.Acme. Inputs. Certificate Tls Challenge - Use
Renewal boolInfo - Validity
Days int
- Account
Key stringPem - Cert
Timeout int - Certificate
Domain string - Certificate
Not stringAfter - Certificate
Not stringBefore - Certificate
P12 string - Certificate
P12Password string - Certificate
Pem string - Certificate
Request stringPem - Certificate
Serial string - Certificate
Url string - Common
Name string - bool
- bool
- Dns
Challenges []CertificateDns Challenge Args - Http
Challenge CertificateHttp Challenge Args - Http
Memcached CertificateChallenge Http Memcached Challenge Args - Http
S3Challenge CertificateHttp S3Challenge Args - Http
Webroot CertificateChallenge Http Webroot Challenge Args - Issuer
Pem string - Key
Type string - Min
Days boolDynamic - Min
Days intRemaining - Must
Staple bool - Pre
Check intDelay - Preferred
Chain string - Private
Key stringPem - Profile string
- Propagation
Wait int - Recursive
Nameservers []string - Renewal
Info stringExplanation Url - Renewal
Info boolIgnore Retry After - Renewal
Info intMax Sleep - Renewal
Info stringRetry After - Renewal
Info stringWindow End - Renewal
Info stringWindow Selected - Renewal
Info stringWindow Start - Revoke
Certificate boolOn Destroy - Revoke
Certificate stringReason - Subject
Alternative []stringNames - Tls
Challenge CertificateTls Challenge Args - Use
Renewal boolInfo - Validity
Days int
- account_
key_ stringpem - cert_
timeout number - certificate_
domain string - certificate_
not_ stringafter - certificate_
not_ stringbefore - certificate_
p12 string - certificate_
p12_ stringpassword - certificate_
pem string - certificate_
request_ stringpem - certificate_
serial string - certificate_
url string - common_
name string - bool
- bool
- dns_
challenges list(object) - http_
challenge object - http_
memcached_ objectchallenge - http_
s3_ objectchallenge - http_
webroot_ objectchallenge - issuer_
pem string - key_
type string - min_
days_ booldynamic - min_
days_ numberremaining - must_
staple bool - pre_
check_ numberdelay - preferred_
chain string - private_
key_ stringpem - profile string
- propagation_
wait number - recursive_
nameservers list(string) - renewal_
info_ stringexplanation_ url - renewal_
info_ boolignore_ retry_ after - renewal_
info_ numbermax_ sleep - renewal_
info_ stringretry_ after - renewal_
info_ stringwindow_ end - renewal_
info_ stringwindow_ selected - renewal_
info_ stringwindow_ start - revoke_
certificate_ boolon_ destroy - revoke_
certificate_ stringreason - subject_
alternative_ list(string)names - tls_
challenge object - use_
renewal_ boolinfo - validity_
days number
- account
Key StringPem - cert
Timeout Integer - certificate
Domain String - certificate
Not StringAfter - certificate
Not StringBefore - certificate
P12 String - certificate
P12Password String - certificate
Pem String - certificate
Request StringPem - certificate
Serial String - certificate
Url String - common
Name String - Boolean
- Boolean
- dns
Challenges List<CertificateDns Challenge> - http
Challenge CertificateHttp Challenge - http
Memcached CertificateChallenge Http Memcached Challenge - http
S3Challenge CertificateHttp S3Challenge - http
Webroot CertificateChallenge Http Webroot Challenge - issuer
Pem String - key
Type String - min
Days BooleanDynamic - min
Days IntegerRemaining - must
Staple Boolean - pre
Check IntegerDelay - preferred
Chain String - private
Key StringPem - profile String
- propagation
Wait Integer - recursive
Nameservers List<String> - renewal
Info StringExplanation Url - renewal
Info BooleanIgnore Retry After - renewal
Info IntegerMax Sleep - renewal
Info StringRetry After - renewal
Info StringWindow End - renewal
Info StringWindow Selected - renewal
Info StringWindow Start - revoke
Certificate BooleanOn Destroy - revoke
Certificate StringReason - subject
Alternative List<String>Names - tls
Challenge CertificateTls Challenge - use
Renewal BooleanInfo - validity
Days Integer
- account
Key stringPem - cert
Timeout number - certificate
Domain string - certificate
Not stringAfter - certificate
Not stringBefore - certificate
P12 string - certificate
P12Password string - certificate
Pem string - certificate
Request stringPem - certificate
Serial string - certificate
Url string - common
Name string - boolean
- boolean
- dns
Challenges CertificateDns Challenge[] - http
Challenge CertificateHttp Challenge - http
Memcached CertificateChallenge Http Memcached Challenge - http
S3Challenge CertificateHttp S3Challenge - http
Webroot CertificateChallenge Http Webroot Challenge - issuer
Pem string - key
Type string - min
Days booleanDynamic - min
Days numberRemaining - must
Staple boolean - pre
Check numberDelay - preferred
Chain string - private
Key stringPem - profile string
- propagation
Wait number - recursive
Nameservers string[] - renewal
Info stringExplanation Url - renewal
Info booleanIgnore Retry After - renewal
Info numberMax Sleep - renewal
Info stringRetry After - renewal
Info stringWindow End - renewal
Info stringWindow Selected - renewal
Info stringWindow Start - revoke
Certificate booleanOn Destroy - revoke
Certificate stringReason - subject
Alternative string[]Names - tls
Challenge CertificateTls Challenge - use
Renewal booleanInfo - validity
Days number
- account_
key_ strpem - cert_
timeout int - certificate_
domain str - certificate_
not_ strafter - certificate_
not_ strbefore - certificate_
p12 str - certificate_
p12_ strpassword - certificate_
pem str - certificate_
request_ strpem - certificate_
serial str - certificate_
url str - common_
name str - bool
- bool
- dns_
challenges Sequence[CertificateDns Challenge Args] - http_
challenge CertificateHttp Challenge Args - http_
memcached_ Certificatechallenge Http Memcached Challenge Args - http_
s3_ Certificatechallenge Http S3Challenge Args - http_
webroot_ Certificatechallenge Http Webroot Challenge Args - issuer_
pem str - key_
type str - min_
days_ booldynamic - min_
days_ intremaining - must_
staple bool - pre_
check_ intdelay - preferred_
chain str - private_
key_ strpem - profile str
- propagation_
wait int - recursive_
nameservers Sequence[str] - renewal_
info_ strexplanation_ url - renewal_
info_ boolignore_ retry_ after - renewal_
info_ intmax_ sleep - renewal_
info_ strretry_ after - renewal_
info_ strwindow_ end - renewal_
info_ strwindow_ selected - renewal_
info_ strwindow_ start - revoke_
certificate_ boolon_ destroy - revoke_
certificate_ strreason - subject_
alternative_ Sequence[str]names - tls_
challenge CertificateTls Challenge Args - use_
renewal_ boolinfo - validity_
days int
- account
Key StringPem - cert
Timeout Number - certificate
Domain String - certificate
Not StringAfter - certificate
Not StringBefore - certificate
P12 String - certificate
P12Password String - certificate
Pem String - certificate
Request StringPem - certificate
Serial String - certificate
Url String - common
Name String - Boolean
- Boolean
- dns
Challenges List<Property Map> - http
Challenge Property Map - http
Memcached Property MapChallenge - http
S3Challenge Property Map - http
Webroot Property MapChallenge - issuer
Pem String - key
Type String - min
Days BooleanDynamic - min
Days NumberRemaining - must
Staple Boolean - pre
Check NumberDelay - preferred
Chain String - private
Key StringPem - profile String
- propagation
Wait Number - recursive
Nameservers List<String> - renewal
Info StringExplanation Url - renewal
Info BooleanIgnore Retry After - renewal
Info NumberMax Sleep - renewal
Info StringRetry After - renewal
Info StringWindow End - renewal
Info StringWindow Selected - renewal
Info StringWindow Start - revoke
Certificate BooleanOn Destroy - revoke
Certificate StringReason - subject
Alternative List<String>Names - tls
Challenge Property Map - use
Renewal BooleanInfo - validity
Days Number
Supporting Types
CertificateDnsChallenge, CertificateDnsChallengeArgs
- Provider string
- Config Dictionary<string, string>
- Match
Domains List<string>
- Provider string
- Config map[string]string
- Match
Domains []string
- provider string
- config map(string)
- match_
domains list(string)
- provider String
- config Map<String,String>
- match
Domains List<String>
- provider string
- config {[key: string]: string}
- match
Domains string[]
- provider str
- config Mapping[str, str]
- match_
domains Sequence[str]
- provider String
- config Map<String>
- match
Domains List<String>
CertificateHttpChallenge, CertificateHttpChallengeArgs
- Port int
- Proxy
Header string
- Port int
- Proxy
Header string
- port number
- proxy_
header string
- port Integer
- proxy
Header String
- port number
- proxy
Header string
- port int
- proxy_
header str
- port Number
- proxy
Header String
CertificateHttpMemcachedChallenge, CertificateHttpMemcachedChallengeArgs
- Hosts List<string>
- Hosts []string
- hosts list(string)
- hosts List<String>
- hosts string[]
- hosts Sequence[str]
- hosts List<String>
CertificateHttpS3Challenge, CertificateHttpS3ChallengeArgs
- S3Bucket string
- S3Bucket string
- s3_
bucket string
- s3Bucket String
- s3Bucket string
- s3_
bucket str
- s3Bucket String
CertificateHttpWebrootChallenge, CertificateHttpWebrootChallengeArgs
- Directory string
- Directory string
- directory string
- directory String
- directory string
- directory str
- directory String
CertificateTlsChallenge, CertificateTlsChallengeArgs
- Port int
- Port int
- port number
- port Integer
- port number
- port int
- port Number
Package Details
- Repository
- acme pulumiverse/pulumi-acme
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the
acmeTerraform Provider.
published on Friday, Sep 25, 2026 by Pulumiverse