1. Registry
  2. Packages
  3. ACME
  4. API Docs
  5. Certificate
Viewing docs for ACME v0.18.0
published on Friday, Sep 25, 2026 by Pulumiverse
ACME
Viewing docs for ACME v0.18.0
published on Friday, Sep 25, 2026 by Pulumiverse

    Create Certificate Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new Certificate(name: string, args: CertificateArgs, opts?: CustomResourceOptions);
    @overload
    def Certificate(resource_name: str,
                    args: CertificateArgs,
                    opts: Optional[ResourceOptions] = None)
    
    @overload
    def Certificate(resource_name: str,
                    opts: Optional[ResourceOptions] = None,
                    account_key_pem: Optional[str] = None,
                    cert_timeout: Optional[int] = None,
                    certificate_p12_password: Optional[str] = None,
                    certificate_request_pem: Optional[str] = None,
                    common_name: Optional[str] = None,
                    deactivate_authorizations: Optional[bool] = None,
                    disable_authoritative_propagation: Optional[bool] = None,
                    dns_challenges: Optional[Sequence[CertificateDnsChallengeArgs]] = None,
                    http_challenge: Optional[CertificateHttpChallengeArgs] = None,
                    http_memcached_challenge: Optional[CertificateHttpMemcachedChallengeArgs] = None,
                    http_s3_challenge: Optional[CertificateHttpS3ChallengeArgs] = None,
                    http_webroot_challenge: Optional[CertificateHttpWebrootChallengeArgs] = None,
                    key_type: Optional[str] = None,
                    min_days_dynamic: Optional[bool] = None,
                    min_days_remaining: Optional[int] = None,
                    must_staple: Optional[bool] = None,
                    pre_check_delay: Optional[int] = None,
                    preferred_chain: Optional[str] = None,
                    profile: Optional[str] = None,
                    propagation_wait: Optional[int] = None,
                    recursive_nameservers: Optional[Sequence[str]] = None,
                    renewal_info_ignore_retry_after: Optional[bool] = None,
                    renewal_info_max_sleep: Optional[int] = None,
                    revoke_certificate_on_destroy: Optional[bool] = None,
                    revoke_certificate_reason: Optional[str] = None,
                    subject_alternative_names: Optional[Sequence[str]] = None,
                    tls_challenge: Optional[CertificateTlsChallengeArgs] = None,
                    use_renewal_info: Optional[bool] = None,
                    validity_days: Optional[int] = None)
    func NewCertificate(ctx *Context, name string, args CertificateArgs, opts ...ResourceOption) (*Certificate, error)
    public Certificate(string name, CertificateArgs args, CustomResourceOptions? opts = null)
    public Certificate(String name, CertificateArgs args)
    public Certificate(String name, CertificateArgs args, CustomResourceOptions options)
    
    type: acme:Certificate
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "acme_certificate" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args CertificateArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args CertificateArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args CertificateArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args CertificateArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args CertificateArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var certificateResource = new Acme.Certificate("certificateResource", new()
    {
        AccountKeyPem = "string",
        CertTimeout = 0,
        CertificateP12Password = "string",
        CertificateRequestPem = "string",
        CommonName = "string",
        DeactivateAuthorizations = false,
        DisableAuthoritativePropagation = false,
        DnsChallenges = new[]
        {
            new Acme.Inputs.CertificateDnsChallengeArgs
            {
                Provider = "string",
                Config = 
                {
                    { "string", "string" },
                },
                MatchDomains = new[]
                {
                    "string",
                },
            },
        },
        HttpChallenge = new Acme.Inputs.CertificateHttpChallengeArgs
        {
            Port = 0,
            ProxyHeader = "string",
        },
        HttpMemcachedChallenge = new Acme.Inputs.CertificateHttpMemcachedChallengeArgs
        {
            Hosts = new[]
            {
                "string",
            },
        },
        HttpS3Challenge = new Acme.Inputs.CertificateHttpS3ChallengeArgs
        {
            S3Bucket = "string",
        },
        HttpWebrootChallenge = new Acme.Inputs.CertificateHttpWebrootChallengeArgs
        {
            Directory = "string",
        },
        KeyType = "string",
        MinDaysDynamic = false,
        MinDaysRemaining = 0,
        MustStaple = false,
        PreCheckDelay = 0,
        PreferredChain = "string",
        Profile = "string",
        PropagationWait = 0,
        RecursiveNameservers = new[]
        {
            "string",
        },
        RenewalInfoIgnoreRetryAfter = false,
        RenewalInfoMaxSleep = 0,
        RevokeCertificateOnDestroy = false,
        RevokeCertificateReason = "string",
        SubjectAlternativeNames = new[]
        {
            "string",
        },
        TlsChallenge = new Acme.Inputs.CertificateTlsChallengeArgs
        {
            Port = 0,
        },
        UseRenewalInfo = false,
        ValidityDays = 0,
    });
    
    example, err := acme.NewCertificate(ctx, "certificateResource", &acme.CertificateArgs{
    	AccountKeyPem:                   pulumi.String("string"),
    	CertTimeout:                     pulumi.Int(0),
    	CertificateP12Password:          pulumi.String("string"),
    	CertificateRequestPem:           pulumi.String("string"),
    	CommonName:                      pulumi.String("string"),
    	DeactivateAuthorizations:        pulumi.Bool(false),
    	DisableAuthoritativePropagation: pulumi.Bool(false),
    	DnsChallenges: acme.CertificateDnsChallengeArray{
    		&acme.CertificateDnsChallengeArgs{
    			Provider: pulumi.String("string"),
    			Config: pulumi.StringMap{
    				"string": pulumi.String("string"),
    			},
    			MatchDomains: pulumi.StringArray{
    				pulumi.String("string"),
    			},
    		},
    	},
    	HttpChallenge: &acme.CertificateHttpChallengeArgs{
    		Port:        pulumi.Int(0),
    		ProxyHeader: pulumi.String("string"),
    	},
    	HttpMemcachedChallenge: &acme.CertificateHttpMemcachedChallengeArgs{
    		Hosts: pulumi.StringArray{
    			pulumi.String("string"),
    		},
    	},
    	HttpS3Challenge: &acme.CertificateHttpS3ChallengeArgs{
    		S3Bucket: pulumi.String("string"),
    	},
    	HttpWebrootChallenge: &acme.CertificateHttpWebrootChallengeArgs{
    		Directory: pulumi.String("string"),
    	},
    	KeyType:          pulumi.String("string"),
    	MinDaysDynamic:   pulumi.Bool(false),
    	MinDaysRemaining: pulumi.Int(0),
    	MustStaple:       pulumi.Bool(false),
    	PreCheckDelay:    pulumi.Int(0),
    	PreferredChain:   pulumi.String("string"),
    	Profile:          pulumi.String("string"),
    	PropagationWait:  pulumi.Int(0),
    	RecursiveNameservers: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	RenewalInfoIgnoreRetryAfter: pulumi.Bool(false),
    	RenewalInfoMaxSleep:         pulumi.Int(0),
    	RevokeCertificateOnDestroy:  pulumi.Bool(false),
    	RevokeCertificateReason:     pulumi.String("string"),
    	SubjectAlternativeNames: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	TlsChallenge: &acme.CertificateTlsChallengeArgs{
    		Port: pulumi.Int(0),
    	},
    	UseRenewalInfo: pulumi.Bool(false),
    	ValidityDays:   pulumi.Int(0),
    })
    
    resource "acme_certificate" "certificateResource" {
      lifecycle {
        create_before_destroy = true
      }
      account_key_pem                   = "string"
      cert_timeout                      = 0
      certificate_p12_password          = "string"
      certificate_request_pem           = "string"
      common_name                       = "string"
      deactivate_authorizations         = false
      disable_authoritative_propagation = false
      dns_challenges {
        provider = "string"
        config = {
          "string" = "string"
        }
        match_domains = ["string"]
      }
      http_challenge = {
        port         = 0
        proxy_header = "string"
      }
      http_memcached_challenge = {
        hosts = ["string"]
      }
      http_s3_challenge = {
        s3_bucket = "string"
      }
      http_webroot_challenge = {
        directory = "string"
      }
      key_type                        = "string"
      min_days_dynamic                = false
      min_days_remaining              = 0
      must_staple                     = false
      pre_check_delay                 = 0
      preferred_chain                 = "string"
      profile                         = "string"
      propagation_wait                = 0
      recursive_nameservers           = ["string"]
      renewal_info_ignore_retry_after = false
      renewal_info_max_sleep          = 0
      revoke_certificate_on_destroy   = false
      revoke_certificate_reason       = "string"
      subject_alternative_names       = ["string"]
      tls_challenge = {
        port = 0
      }
      use_renewal_info = false
      validity_days    = 0
    }
    
    var certificateResource = new Certificate("certificateResource", CertificateArgs.builder()
        .accountKeyPem("string")
        .certTimeout(0)
        .certificateP12Password("string")
        .certificateRequestPem("string")
        .commonName("string")
        .deactivateAuthorizations(false)
        .disableAuthoritativePropagation(false)
        .dnsChallenges(CertificateDnsChallengeArgs.builder()
            .provider("string")
            .config(Map.of("string", "string"))
            .matchDomains("string")
            .build())
        .httpChallenge(CertificateHttpChallengeArgs.builder()
            .port(0)
            .proxyHeader("string")
            .build())
        .httpMemcachedChallenge(CertificateHttpMemcachedChallengeArgs.builder()
            .hosts("string")
            .build())
        .httpS3Challenge(CertificateHttpS3ChallengeArgs.builder()
            .s3Bucket("string")
            .build())
        .httpWebrootChallenge(CertificateHttpWebrootChallengeArgs.builder()
            .directory("string")
            .build())
        .keyType("string")
        .minDaysDynamic(false)
        .minDaysRemaining(0)
        .mustStaple(false)
        .preCheckDelay(0)
        .preferredChain("string")
        .profile("string")
        .propagationWait(0)
        .recursiveNameservers("string")
        .renewalInfoIgnoreRetryAfter(false)
        .renewalInfoMaxSleep(0)
        .revokeCertificateOnDestroy(false)
        .revokeCertificateReason("string")
        .subjectAlternativeNames("string")
        .tlsChallenge(CertificateTlsChallengeArgs.builder()
            .port(0)
            .build())
        .useRenewalInfo(false)
        .validityDays(0)
        .build());
    
    certificate_resource = acme.Certificate("certificateResource",
        account_key_pem="string",
        cert_timeout=0,
        certificate_p12_password="string",
        certificate_request_pem="string",
        common_name="string",
        deactivate_authorizations=False,
        disable_authoritative_propagation=False,
        dns_challenges=[{
            "provider": "string",
            "config": {
                "string": "string",
            },
            "match_domains": ["string"],
        }],
        http_challenge={
            "port": 0,
            "proxy_header": "string",
        },
        http_memcached_challenge={
            "hosts": ["string"],
        },
        http_s3_challenge={
            "s3_bucket": "string",
        },
        http_webroot_challenge={
            "directory": "string",
        },
        key_type="string",
        min_days_dynamic=False,
        min_days_remaining=0,
        must_staple=False,
        pre_check_delay=0,
        preferred_chain="string",
        profile="string",
        propagation_wait=0,
        recursive_nameservers=["string"],
        renewal_info_ignore_retry_after=False,
        renewal_info_max_sleep=0,
        revoke_certificate_on_destroy=False,
        revoke_certificate_reason="string",
        subject_alternative_names=["string"],
        tls_challenge={
            "port": 0,
        },
        use_renewal_info=False,
        validity_days=0)
    
    const certificateResource = new acme.Certificate("certificateResource", {
        accountKeyPem: "string",
        certTimeout: 0,
        certificateP12Password: "string",
        certificateRequestPem: "string",
        commonName: "string",
        deactivateAuthorizations: false,
        disableAuthoritativePropagation: false,
        dnsChallenges: [{
            provider: "string",
            config: {
                string: "string",
            },
            matchDomains: ["string"],
        }],
        httpChallenge: {
            port: 0,
            proxyHeader: "string",
        },
        httpMemcachedChallenge: {
            hosts: ["string"],
        },
        httpS3Challenge: {
            s3Bucket: "string",
        },
        httpWebrootChallenge: {
            directory: "string",
        },
        keyType: "string",
        minDaysDynamic: false,
        minDaysRemaining: 0,
        mustStaple: false,
        preCheckDelay: 0,
        preferredChain: "string",
        profile: "string",
        propagationWait: 0,
        recursiveNameservers: ["string"],
        renewalInfoIgnoreRetryAfter: false,
        renewalInfoMaxSleep: 0,
        revokeCertificateOnDestroy: false,
        revokeCertificateReason: "string",
        subjectAlternativeNames: ["string"],
        tlsChallenge: {
            port: 0,
        },
        useRenewalInfo: false,
        validityDays: 0,
    });
    
    type: acme:Certificate
    properties:
        accountKeyPem: string
        certTimeout: 0
        certificateP12Password: string
        certificateRequestPem: string
        commonName: string
        deactivateAuthorizations: false
        disableAuthoritativePropagation: false
        dnsChallenges:
            - config:
                string: string
              matchDomains:
                - string
              provider: string
        httpChallenge:
            port: 0
            proxyHeader: string
        httpMemcachedChallenge:
            hosts:
                - string
        httpS3Challenge:
            s3Bucket: string
        httpWebrootChallenge:
            directory: string
        keyType: string
        minDaysDynamic: false
        minDaysRemaining: 0
        mustStaple: false
        preCheckDelay: 0
        preferredChain: string
        profile: string
        propagationWait: 0
        recursiveNameservers:
            - string
        renewalInfoIgnoreRetryAfter: false
        renewalInfoMaxSleep: 0
        revokeCertificateOnDestroy: false
        revokeCertificateReason: string
        subjectAlternativeNames:
            - string
        tlsChallenge:
            port: 0
        useRenewalInfo: false
        validityDays: 0
    

    Certificate Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The Certificate resource accepts the following input properties:

    AccountKeyPem string
    CertTimeout int
    CertificateP12Password string
    CertificateRequestPem string
    CommonName string
    DeactivateAuthorizations bool
    DisableAuthoritativePropagation bool
    DnsChallenges List<Pulumiverse.Acme.Inputs.CertificateDnsChallenge>
    HttpChallenge Pulumiverse.Acme.Inputs.CertificateHttpChallenge
    HttpMemcachedChallenge Pulumiverse.Acme.Inputs.CertificateHttpMemcachedChallenge
    HttpS3Challenge Pulumiverse.Acme.Inputs.CertificateHttpS3Challenge
    HttpWebrootChallenge Pulumiverse.Acme.Inputs.CertificateHttpWebrootChallenge
    KeyType string
    MinDaysDynamic bool
    MinDaysRemaining int
    MustStaple bool
    PreCheckDelay int
    PreferredChain string
    Profile string
    PropagationWait int
    RecursiveNameservers List<string>
    RenewalInfoIgnoreRetryAfter bool
    RenewalInfoMaxSleep int
    RevokeCertificateOnDestroy bool
    RevokeCertificateReason string
    SubjectAlternativeNames List<string>
    TlsChallenge Pulumiverse.Acme.Inputs.CertificateTlsChallenge
    UseRenewalInfo bool
    ValidityDays int
    AccountKeyPem string
    CertTimeout int
    CertificateP12Password string
    CertificateRequestPem string
    CommonName string
    DeactivateAuthorizations bool
    DisableAuthoritativePropagation bool
    DnsChallenges []CertificateDnsChallengeArgs
    HttpChallenge CertificateHttpChallengeArgs
    HttpMemcachedChallenge CertificateHttpMemcachedChallengeArgs
    HttpS3Challenge CertificateHttpS3ChallengeArgs
    HttpWebrootChallenge CertificateHttpWebrootChallengeArgs
    KeyType string
    MinDaysDynamic bool
    MinDaysRemaining int
    MustStaple bool
    PreCheckDelay int
    PreferredChain string
    Profile string
    PropagationWait int
    RecursiveNameservers []string
    RenewalInfoIgnoreRetryAfter bool
    RenewalInfoMaxSleep int
    RevokeCertificateOnDestroy bool
    RevokeCertificateReason string
    SubjectAlternativeNames []string
    TlsChallenge CertificateTlsChallengeArgs
    UseRenewalInfo bool
    ValidityDays int
    accountKeyPem String
    certTimeout Integer
    certificateP12Password String
    certificateRequestPem String
    commonName String
    deactivateAuthorizations Boolean
    disableAuthoritativePropagation Boolean
    dnsChallenges List<CertificateDnsChallenge>
    httpChallenge CertificateHttpChallenge
    httpMemcachedChallenge CertificateHttpMemcachedChallenge
    httpS3Challenge CertificateHttpS3Challenge
    httpWebrootChallenge CertificateHttpWebrootChallenge
    keyType String
    minDaysDynamic Boolean
    minDaysRemaining Integer
    mustStaple Boolean
    preCheckDelay Integer
    preferredChain String
    profile String
    propagationWait Integer
    recursiveNameservers List<String>
    renewalInfoIgnoreRetryAfter Boolean
    renewalInfoMaxSleep Integer
    revokeCertificateOnDestroy Boolean
    revokeCertificateReason String
    subjectAlternativeNames List<String>
    tlsChallenge CertificateTlsChallenge
    useRenewalInfo Boolean
    validityDays Integer
    accountKeyPem string
    certTimeout number
    certificateP12Password string
    certificateRequestPem string
    commonName string
    deactivateAuthorizations boolean
    disableAuthoritativePropagation boolean
    dnsChallenges CertificateDnsChallenge[]
    httpChallenge CertificateHttpChallenge
    httpMemcachedChallenge CertificateHttpMemcachedChallenge
    httpS3Challenge CertificateHttpS3Challenge
    httpWebrootChallenge CertificateHttpWebrootChallenge
    keyType string
    minDaysDynamic boolean
    minDaysRemaining number
    mustStaple boolean
    preCheckDelay number
    preferredChain string
    profile string
    propagationWait number
    recursiveNameservers string[]
    renewalInfoIgnoreRetryAfter boolean
    renewalInfoMaxSleep number
    revokeCertificateOnDestroy boolean
    revokeCertificateReason string
    subjectAlternativeNames string[]
    tlsChallenge CertificateTlsChallenge
    useRenewalInfo boolean
    validityDays number
    account_key_pem str
    cert_timeout int
    certificate_p12_password str
    certificate_request_pem str
    common_name str
    deactivate_authorizations bool
    disable_authoritative_propagation bool
    dns_challenges Sequence[CertificateDnsChallengeArgs]
    http_challenge CertificateHttpChallengeArgs
    http_memcached_challenge CertificateHttpMemcachedChallengeArgs
    http_s3_challenge CertificateHttpS3ChallengeArgs
    http_webroot_challenge CertificateHttpWebrootChallengeArgs
    key_type str
    min_days_dynamic bool
    min_days_remaining int
    must_staple bool
    pre_check_delay int
    preferred_chain str
    profile str
    propagation_wait int
    recursive_nameservers Sequence[str]
    renewal_info_ignore_retry_after bool
    renewal_info_max_sleep int
    revoke_certificate_on_destroy bool
    revoke_certificate_reason str
    subject_alternative_names Sequence[str]
    tls_challenge CertificateTlsChallengeArgs
    use_renewal_info bool
    validity_days int

    Outputs

    All input properties are implicitly available as output properties. Additionally, the Certificate resource produces the following output properties:

    Look up Existing Certificate Resource

    Get an existing Certificate resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: CertificateState, opts?: CustomResourceOptions): Certificate
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            account_key_pem: Optional[str] = None,
            cert_timeout: Optional[int] = None,
            certificate_domain: Optional[str] = None,
            certificate_not_after: Optional[str] = None,
            certificate_not_before: Optional[str] = None,
            certificate_p12: Optional[str] = None,
            certificate_p12_password: Optional[str] = None,
            certificate_pem: Optional[str] = None,
            certificate_request_pem: Optional[str] = None,
            certificate_serial: Optional[str] = None,
            certificate_url: Optional[str] = None,
            common_name: Optional[str] = None,
            deactivate_authorizations: Optional[bool] = None,
            disable_authoritative_propagation: Optional[bool] = None,
            dns_challenges: Optional[Sequence[CertificateDnsChallengeArgs]] = None,
            http_challenge: Optional[CertificateHttpChallengeArgs] = None,
            http_memcached_challenge: Optional[CertificateHttpMemcachedChallengeArgs] = None,
            http_s3_challenge: Optional[CertificateHttpS3ChallengeArgs] = None,
            http_webroot_challenge: Optional[CertificateHttpWebrootChallengeArgs] = None,
            issuer_pem: Optional[str] = None,
            key_type: Optional[str] = None,
            min_days_dynamic: Optional[bool] = None,
            min_days_remaining: Optional[int] = None,
            must_staple: Optional[bool] = None,
            pre_check_delay: Optional[int] = None,
            preferred_chain: Optional[str] = None,
            private_key_pem: Optional[str] = None,
            profile: Optional[str] = None,
            propagation_wait: Optional[int] = None,
            recursive_nameservers: Optional[Sequence[str]] = None,
            renewal_info_explanation_url: Optional[str] = None,
            renewal_info_ignore_retry_after: Optional[bool] = None,
            renewal_info_max_sleep: Optional[int] = None,
            renewal_info_retry_after: Optional[str] = None,
            renewal_info_window_end: Optional[str] = None,
            renewal_info_window_selected: Optional[str] = None,
            renewal_info_window_start: Optional[str] = None,
            revoke_certificate_on_destroy: Optional[bool] = None,
            revoke_certificate_reason: Optional[str] = None,
            subject_alternative_names: Optional[Sequence[str]] = None,
            tls_challenge: Optional[CertificateTlsChallengeArgs] = None,
            use_renewal_info: Optional[bool] = None,
            validity_days: Optional[int] = None) -> Certificate
    func GetCertificate(ctx *Context, name string, id IDInput, state *CertificateState, opts ...ResourceOption) (*Certificate, error)
    public static Certificate Get(string name, Input<string> id, CertificateState? state, CustomResourceOptions? opts = null)
    public static Certificate get(String name, Output<String> id, CertificateState state, CustomResourceOptions options)
    resources:  _:    type: acme:Certificate    get:      id: ${id}
    import {
      to = acme_certificate.example
      id = "${id}"
    }
    
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    AccountKeyPem string
    CertTimeout int
    CertificateDomain string
    CertificateNotAfter string
    CertificateNotBefore string
    CertificateP12 string
    CertificateP12Password string
    CertificatePem string
    CertificateRequestPem string
    CertificateSerial string
    CertificateUrl string
    CommonName string
    DeactivateAuthorizations bool
    DisableAuthoritativePropagation bool
    DnsChallenges List<Pulumiverse.Acme.Inputs.CertificateDnsChallenge>
    HttpChallenge Pulumiverse.Acme.Inputs.CertificateHttpChallenge
    HttpMemcachedChallenge Pulumiverse.Acme.Inputs.CertificateHttpMemcachedChallenge
    HttpS3Challenge Pulumiverse.Acme.Inputs.CertificateHttpS3Challenge
    HttpWebrootChallenge Pulumiverse.Acme.Inputs.CertificateHttpWebrootChallenge
    IssuerPem string
    KeyType string
    MinDaysDynamic bool
    MinDaysRemaining int
    MustStaple bool
    PreCheckDelay int
    PreferredChain string
    PrivateKeyPem string
    Profile string
    PropagationWait int
    RecursiveNameservers List<string>
    RenewalInfoExplanationUrl string
    RenewalInfoIgnoreRetryAfter bool
    RenewalInfoMaxSleep int
    RenewalInfoRetryAfter string
    RenewalInfoWindowEnd string
    RenewalInfoWindowSelected string
    RenewalInfoWindowStart string
    RevokeCertificateOnDestroy bool
    RevokeCertificateReason string
    SubjectAlternativeNames List<string>
    TlsChallenge Pulumiverse.Acme.Inputs.CertificateTlsChallenge
    UseRenewalInfo bool
    ValidityDays int
    AccountKeyPem string
    CertTimeout int
    CertificateDomain string
    CertificateNotAfter string
    CertificateNotBefore string
    CertificateP12 string
    CertificateP12Password string
    CertificatePem string
    CertificateRequestPem string
    CertificateSerial string
    CertificateUrl string
    CommonName string
    DeactivateAuthorizations bool
    DisableAuthoritativePropagation bool
    DnsChallenges []CertificateDnsChallengeArgs
    HttpChallenge CertificateHttpChallengeArgs
    HttpMemcachedChallenge CertificateHttpMemcachedChallengeArgs
    HttpS3Challenge CertificateHttpS3ChallengeArgs
    HttpWebrootChallenge CertificateHttpWebrootChallengeArgs
    IssuerPem string
    KeyType string
    MinDaysDynamic bool
    MinDaysRemaining int
    MustStaple bool
    PreCheckDelay int
    PreferredChain string
    PrivateKeyPem string
    Profile string
    PropagationWait int
    RecursiveNameservers []string
    RenewalInfoExplanationUrl string
    RenewalInfoIgnoreRetryAfter bool
    RenewalInfoMaxSleep int
    RenewalInfoRetryAfter string
    RenewalInfoWindowEnd string
    RenewalInfoWindowSelected string
    RenewalInfoWindowStart string
    RevokeCertificateOnDestroy bool
    RevokeCertificateReason string
    SubjectAlternativeNames []string
    TlsChallenge CertificateTlsChallengeArgs
    UseRenewalInfo bool
    ValidityDays int
    account_key_pem string
    cert_timeout number
    certificate_domain string
    certificate_not_after string
    certificate_not_before string
    certificate_p12 string
    certificate_p12_password string
    certificate_pem string
    certificate_request_pem string
    certificate_serial string
    certificate_url string
    common_name string
    deactivate_authorizations bool
    disable_authoritative_propagation bool
    dns_challenges list(object)
    http_challenge object
    http_memcached_challenge object
    http_s3_challenge object
    http_webroot_challenge object
    issuer_pem string
    key_type string
    min_days_dynamic bool
    min_days_remaining number
    must_staple bool
    pre_check_delay number
    preferred_chain string
    private_key_pem string
    profile string
    propagation_wait number
    recursive_nameservers list(string)
    renewal_info_explanation_url string
    renewal_info_ignore_retry_after bool
    renewal_info_max_sleep number
    renewal_info_retry_after string
    renewal_info_window_end string
    renewal_info_window_selected string
    renewal_info_window_start string
    revoke_certificate_on_destroy bool
    revoke_certificate_reason string
    subject_alternative_names list(string)
    tls_challenge object
    use_renewal_info bool
    validity_days number
    accountKeyPem String
    certTimeout Integer
    certificateDomain String
    certificateNotAfter String
    certificateNotBefore String
    certificateP12 String
    certificateP12Password String
    certificatePem String
    certificateRequestPem String
    certificateSerial String
    certificateUrl String
    commonName String
    deactivateAuthorizations Boolean
    disableAuthoritativePropagation Boolean
    dnsChallenges List<CertificateDnsChallenge>
    httpChallenge CertificateHttpChallenge
    httpMemcachedChallenge CertificateHttpMemcachedChallenge
    httpS3Challenge CertificateHttpS3Challenge
    httpWebrootChallenge CertificateHttpWebrootChallenge
    issuerPem String
    keyType String
    minDaysDynamic Boolean
    minDaysRemaining Integer
    mustStaple Boolean
    preCheckDelay Integer
    preferredChain String
    privateKeyPem String
    profile String
    propagationWait Integer
    recursiveNameservers List<String>
    renewalInfoExplanationUrl String
    renewalInfoIgnoreRetryAfter Boolean
    renewalInfoMaxSleep Integer
    renewalInfoRetryAfter String
    renewalInfoWindowEnd String
    renewalInfoWindowSelected String
    renewalInfoWindowStart String
    revokeCertificateOnDestroy Boolean
    revokeCertificateReason String
    subjectAlternativeNames List<String>
    tlsChallenge CertificateTlsChallenge
    useRenewalInfo Boolean
    validityDays Integer
    accountKeyPem string
    certTimeout number
    certificateDomain string
    certificateNotAfter string
    certificateNotBefore string
    certificateP12 string
    certificateP12Password string
    certificatePem string
    certificateRequestPem string
    certificateSerial string
    certificateUrl string
    commonName string
    deactivateAuthorizations boolean
    disableAuthoritativePropagation boolean
    dnsChallenges CertificateDnsChallenge[]
    httpChallenge CertificateHttpChallenge
    httpMemcachedChallenge CertificateHttpMemcachedChallenge
    httpS3Challenge CertificateHttpS3Challenge
    httpWebrootChallenge CertificateHttpWebrootChallenge
    issuerPem string
    keyType string
    minDaysDynamic boolean
    minDaysRemaining number
    mustStaple boolean
    preCheckDelay number
    preferredChain string
    privateKeyPem string
    profile string
    propagationWait number
    recursiveNameservers string[]
    renewalInfoExplanationUrl string
    renewalInfoIgnoreRetryAfter boolean
    renewalInfoMaxSleep number
    renewalInfoRetryAfter string
    renewalInfoWindowEnd string
    renewalInfoWindowSelected string
    renewalInfoWindowStart string
    revokeCertificateOnDestroy boolean
    revokeCertificateReason string
    subjectAlternativeNames string[]
    tlsChallenge CertificateTlsChallenge
    useRenewalInfo boolean
    validityDays number
    account_key_pem str
    cert_timeout int
    certificate_domain str
    certificate_not_after str
    certificate_not_before str
    certificate_p12 str
    certificate_p12_password str
    certificate_pem str
    certificate_request_pem str
    certificate_serial str
    certificate_url str
    common_name str
    deactivate_authorizations bool
    disable_authoritative_propagation bool
    dns_challenges Sequence[CertificateDnsChallengeArgs]
    http_challenge CertificateHttpChallengeArgs
    http_memcached_challenge CertificateHttpMemcachedChallengeArgs
    http_s3_challenge CertificateHttpS3ChallengeArgs
    http_webroot_challenge CertificateHttpWebrootChallengeArgs
    issuer_pem str
    key_type str
    min_days_dynamic bool
    min_days_remaining int
    must_staple bool
    pre_check_delay int
    preferred_chain str
    private_key_pem str
    profile str
    propagation_wait int
    recursive_nameservers Sequence[str]
    renewal_info_explanation_url str
    renewal_info_ignore_retry_after bool
    renewal_info_max_sleep int
    renewal_info_retry_after str
    renewal_info_window_end str
    renewal_info_window_selected str
    renewal_info_window_start str
    revoke_certificate_on_destroy bool
    revoke_certificate_reason str
    subject_alternative_names Sequence[str]
    tls_challenge CertificateTlsChallengeArgs
    use_renewal_info bool
    validity_days int
    accountKeyPem String
    certTimeout Number
    certificateDomain String
    certificateNotAfter String
    certificateNotBefore String
    certificateP12 String
    certificateP12Password String
    certificatePem String
    certificateRequestPem String
    certificateSerial String
    certificateUrl String
    commonName String
    deactivateAuthorizations Boolean
    disableAuthoritativePropagation Boolean
    dnsChallenges List<Property Map>
    httpChallenge Property Map
    httpMemcachedChallenge Property Map
    httpS3Challenge Property Map
    httpWebrootChallenge Property Map
    issuerPem String
    keyType String
    minDaysDynamic Boolean
    minDaysRemaining Number
    mustStaple Boolean
    preCheckDelay Number
    preferredChain String
    privateKeyPem String
    profile String
    propagationWait Number
    recursiveNameservers List<String>
    renewalInfoExplanationUrl String
    renewalInfoIgnoreRetryAfter Boolean
    renewalInfoMaxSleep Number
    renewalInfoRetryAfter String
    renewalInfoWindowEnd String
    renewalInfoWindowSelected String
    renewalInfoWindowStart String
    revokeCertificateOnDestroy Boolean
    revokeCertificateReason String
    subjectAlternativeNames List<String>
    tlsChallenge Property Map
    useRenewalInfo Boolean
    validityDays Number

    Supporting Types

    CertificateDnsChallenge, CertificateDnsChallengeArgs

    Provider string
    Config Dictionary<string, string>
    MatchDomains List<string>
    Provider string
    Config map[string]string
    MatchDomains []string
    provider string
    config map(string)
    match_domains list(string)
    provider String
    config Map<String,String>
    matchDomains List<String>
    provider string
    config {[key: string]: string}
    matchDomains string[]
    provider str
    config Mapping[str, str]
    match_domains Sequence[str]
    provider String
    config Map<String>
    matchDomains List<String>

    CertificateHttpChallenge, CertificateHttpChallengeArgs

    Port int
    ProxyHeader string
    Port int
    ProxyHeader string
    port number
    proxy_header string
    port Integer
    proxyHeader String
    port number
    proxyHeader string
    port Number
    proxyHeader String

    CertificateHttpMemcachedChallenge, CertificateHttpMemcachedChallengeArgs

    Hosts List<string>
    Hosts []string
    hosts list(string)
    hosts List<String>
    hosts string[]
    hosts Sequence[str]
    hosts List<String>

    CertificateHttpS3Challenge, CertificateHttpS3ChallengeArgs

    S3Bucket string
    S3Bucket string
    s3_bucket string
    s3Bucket String
    s3Bucket string
    s3Bucket String

    CertificateHttpWebrootChallenge, CertificateHttpWebrootChallengeArgs

    Directory string
    Directory string
    directory string
    directory String
    directory string
    directory String

    CertificateTlsChallenge, CertificateTlsChallengeArgs

    Port int
    Port int
    port number
    port Integer
    port number
    port int
    port Number

    Package Details

    Repository
    acme pulumiverse/pulumi-acme
    License
    Apache-2.0
    Notes
    This Pulumi package is based on the acme Terraform Provider.
    ACME
    Viewing docs for ACME v0.18.0
    published on Friday, Sep 25, 2026 by Pulumiverse

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial