published on Monday, Sep 21, 2026 by Formal
published on Monday, Sep 21, 2026 by Formal
A Native User the Formal connector authenticates to a Resource as. The Resource decides which Native User a session uses through its formal.ResourceNativeUserSelection expression.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as formal from "@formalco/pulumi";
const config = new pulumi.Config();
const analyticsAdminPassword = config.require("analyticsAdminPassword");
const db = new formal.Resource("db", {
name: "analytics-postgres",
hostname: "analytics.internal",
technology: "postgres",
port: 5432,
nativeUsersV3Enabled: true,
});
// Username and password, read from an environment variable on the connector.
const basic = new formal.NativeUserV3("basic", {
basic: {
password: {
environmentVariable: "ANALYTICS_ADMIN_PASSWORD",
},
username: "app_admin",
},
resourceId: db.id,
label: "admin",
});
// Username and password, with the password passed as a write-only value so it
// never lands in Terraform state. Increment literal_wo_version to rotate it.
const basicWriteOnly = new formal.NativeUserV3("basic_write_only", {
basic: {
password: {
literalWo: analyticsAdminPassword,
literalWoVersion: 1,
},
username: "app_admin",
},
resourceId: db.id,
label: "admin-write-only",
});
// AWS IAM, inheriting the role from the connector's environment.
const awsIam = new formal.NativeUserV3("aws_iam", {
awsIam: {
username: "app_iam",
},
resourceId: db.id,
label: "iam",
});
const api = new formal.Resource("api", {
name: "billing-api",
hostname: "billing.internal",
technology: "http",
port: 443,
nativeUsersV3Enabled: true,
});
const bearerToken = new formal.NativeUserV3("bearer_token", {
httpBearer: {
token: {
environmentVariable: "BILLING_API_TOKEN",
},
header: "Authorization",
},
resourceId: api.id,
label: "service-account",
});
// Credentials resolved at connection time by a hook running on the connector,
// for example to mint short-lived credentials from a secrets manager.
const fromHook = new formal.NativeUserV3("from_hook", {
hook: {
outputType: "basic",
allowlistedEnvVariables: [
"FORMAL_ENV_USER",
"FORMAL_ENV_PASSWORD",
],
code: `export default async function (_input, env) {
return {
username: env.FORMAL_ENV_USER,
password: env.FORMAL_ENV_PASSWORD,
};
}
`,
},
resourceId: db.id,
label: "dynamic",
});
import pulumi
import pulumi_formal as formal
config = pulumi.Config()
analytics_admin_password = config.require("analyticsAdminPassword")
db = formal.Resource("db",
name="analytics-postgres",
hostname="analytics.internal",
technology="postgres",
port=5432,
native_users_v3_enabled=True)
# Username and password, read from an environment variable on the connector.
basic = formal.NativeUserV3("basic",
basic={
"password": {
"environment_variable": "ANALYTICS_ADMIN_PASSWORD",
},
"username": "app_admin",
},
resource_id=db.id,
label="admin")
# Username and password, with the password passed as a write-only value so it
# never lands in Terraform state. Increment literal_wo_version to rotate it.
basic_write_only = formal.NativeUserV3("basic_write_only",
basic={
"password": {
"literal_wo": analytics_admin_password,
"literal_wo_version": 1,
},
"username": "app_admin",
},
resource_id=db.id,
label="admin-write-only")
# AWS IAM, inheriting the role from the connector's environment.
aws_iam = formal.NativeUserV3("aws_iam",
aws_iam={
"username": "app_iam",
},
resource_id=db.id,
label="iam")
api = formal.Resource("api",
name="billing-api",
hostname="billing.internal",
technology="http",
port=443,
native_users_v3_enabled=True)
bearer_token = formal.NativeUserV3("bearer_token",
http_bearer={
"token": {
"environment_variable": "BILLING_API_TOKEN",
},
"header": "Authorization",
},
resource_id=api.id,
label="service-account")
# Credentials resolved at connection time by a hook running on the connector,
# for example to mint short-lived credentials from a secrets manager.
from_hook = formal.NativeUserV3("from_hook",
hook={
"output_type": "basic",
"allowlisted_env_variables": [
"FORMAL_ENV_USER",
"FORMAL_ENV_PASSWORD",
],
"code": """export default async function (_input, env) {
return {
username: env.FORMAL_ENV_USER,
password: env.FORMAL_ENV_PASSWORD,
};
}
""",
},
resource_id=db.id,
label="dynamic")
package main
import (
"github.com/formalco/pulumi-formal/sdk/go/formal"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi/config"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
cfg := config.New(ctx, "")
analyticsAdminPassword := cfg.Require("analyticsAdminPassword")
db, err := formal.NewResource(ctx, "db", &formal.ResourceArgs{
Name: pulumi.String("analytics-postgres"),
Hostname: pulumi.String("analytics.internal"),
Technology: pulumi.String("postgres"),
Port: pulumi.Int(5432),
NativeUsersV3Enabled: pulumi.Bool(true),
})
if err != nil {
return err
}
// Username and password, read from an environment variable on the connector.
_, err = formal.NewNativeUserV3(ctx, "basic", &formal.NativeUserV3Args{
Basic: &formal.NativeUserV3BasicArgs{
Password: &formal.NativeUserV3BasicPasswordArgs{
EnvironmentVariable: pulumi.String("ANALYTICS_ADMIN_PASSWORD"),
},
Username: pulumi.String("app_admin"),
},
ResourceId: db.ID(),
Label: pulumi.String("admin"),
})
if err != nil {
return err
}
// Username and password, with the password passed as a write-only value so it
// never lands in Terraform state. Increment literal_wo_version to rotate it.
_, err = formal.NewNativeUserV3(ctx, "basic_write_only", &formal.NativeUserV3Args{
Basic: &formal.NativeUserV3BasicArgs{
Password: &formal.NativeUserV3BasicPasswordArgs{
LiteralWo: pulumi.String(pulumi.String(analyticsAdminPassword)),
LiteralWoVersion: pulumi.Int(1),
},
Username: pulumi.String("app_admin"),
},
ResourceId: db.ID(),
Label: pulumi.String("admin-write-only"),
})
if err != nil {
return err
}
// AWS IAM, inheriting the role from the connector's environment.
_, err = formal.NewNativeUserV3(ctx, "aws_iam", &formal.NativeUserV3Args{
AwsIam: &formal.NativeUserV3AwsIamArgs{
Username: pulumi.String("app_iam"),
},
ResourceId: db.ID(),
Label: pulumi.String("iam"),
})
if err != nil {
return err
}
api, err := formal.NewResource(ctx, "api", &formal.ResourceArgs{
Name: pulumi.String("billing-api"),
Hostname: pulumi.String("billing.internal"),
Technology: pulumi.String("http"),
Port: pulumi.Int(443),
NativeUsersV3Enabled: pulumi.Bool(true),
})
if err != nil {
return err
}
_, err = formal.NewNativeUserV3(ctx, "bearer_token", &formal.NativeUserV3Args{
HttpBearer: &formal.NativeUserV3HttpBearerArgs{
Token: &formal.NativeUserV3HttpBearerTokenArgs{
EnvironmentVariable: pulumi.String("BILLING_API_TOKEN"),
},
Header: pulumi.String("Authorization"),
},
ResourceId: api.ID(),
Label: pulumi.String("service-account"),
})
if err != nil {
return err
}
// Credentials resolved at connection time by a hook running on the connector,
// for example to mint short-lived credentials from a secrets manager.
_, err = formal.NewNativeUserV3(ctx, "from_hook", &formal.NativeUserV3Args{
Hook: &formal.NativeUserV3HookArgs{
OutputType: pulumi.String("basic"),
AllowlistedEnvVariables: pulumi.StringArray{
pulumi.String("FORMAL_ENV_USER"),
pulumi.String("FORMAL_ENV_PASSWORD"),
},
Code: pulumi.String(`export default async function (_input, env) {
return {
username: env.FORMAL_ENV_USER,
password: env.FORMAL_ENV_PASSWORD,
};
}
`),
},
ResourceId: db.ID(),
Label: pulumi.String("dynamic"),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Pulumi = Formal.Pulumi;
return await Deployment.RunAsync(() =>
{
var config = new Config();
var analyticsAdminPassword = config.Require("analyticsAdminPassword");
var db = new Pulumi.Resource("db", new()
{
Name = "analytics-postgres",
Hostname = "analytics.internal",
Technology = "postgres",
Port = 5432,
NativeUsersV3Enabled = true,
});
// Username and password, read from an environment variable on the connector.
var basic = new Pulumi.NativeUserV3("basic", new()
{
Basic = new Pulumi.Inputs.NativeUserV3BasicArgs
{
Password = new Pulumi.Inputs.NativeUserV3BasicPasswordArgs
{
EnvironmentVariable = "ANALYTICS_ADMIN_PASSWORD",
},
Username = "app_admin",
},
ResourceId = db.Id,
Label = "admin",
});
// Username and password, with the password passed as a write-only value so it
// never lands in Terraform state. Increment literal_wo_version to rotate it.
var basicWriteOnly = new Pulumi.NativeUserV3("basic_write_only", new()
{
Basic = new Pulumi.Inputs.NativeUserV3BasicArgs
{
Password = new Pulumi.Inputs.NativeUserV3BasicPasswordArgs
{
LiteralWo = analyticsAdminPassword,
LiteralWoVersion = 1,
},
Username = "app_admin",
},
ResourceId = db.Id,
Label = "admin-write-only",
});
// AWS IAM, inheriting the role from the connector's environment.
var awsIam = new Pulumi.NativeUserV3("aws_iam", new()
{
AwsIam = new Pulumi.Inputs.NativeUserV3AwsIamArgs
{
Username = "app_iam",
},
ResourceId = db.Id,
Label = "iam",
});
var api = new Pulumi.Resource("api", new()
{
Name = "billing-api",
Hostname = "billing.internal",
Technology = "http",
Port = 443,
NativeUsersV3Enabled = true,
});
var bearerToken = new Pulumi.NativeUserV3("bearer_token", new()
{
HttpBearer = new Pulumi.Inputs.NativeUserV3HttpBearerArgs
{
Token = new Pulumi.Inputs.NativeUserV3HttpBearerTokenArgs
{
EnvironmentVariable = "BILLING_API_TOKEN",
},
Header = "Authorization",
},
ResourceId = api.Id,
Label = "service-account",
});
// Credentials resolved at connection time by a hook running on the connector,
// for example to mint short-lived credentials from a secrets manager.
var fromHook = new Pulumi.NativeUserV3("from_hook", new()
{
Hook = new Pulumi.Inputs.NativeUserV3HookArgs
{
OutputType = "basic",
AllowlistedEnvVariables = new[]
{
"FORMAL_ENV_USER",
"FORMAL_ENV_PASSWORD",
},
Code = @"export default async function (_input, env) {
return {
username: env.FORMAL_ENV_USER,
password: env.FORMAL_ENV_PASSWORD,
};
}
",
},
ResourceId = db.Id,
Label = "dynamic",
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.formal.Resource;
import com.pulumi.formal.ResourceArgs;
import com.pulumi.formal.NativeUserV3;
import com.pulumi.formal.NativeUserV3Args;
import com.pulumi.formal.inputs.NativeUserV3BasicArgs;
import com.pulumi.formal.inputs.NativeUserV3BasicPasswordArgs;
import com.pulumi.formal.inputs.NativeUserV3AwsIamArgs;
import com.pulumi.formal.inputs.NativeUserV3HttpBearerArgs;
import com.pulumi.formal.inputs.NativeUserV3HttpBearerTokenArgs;
import com.pulumi.formal.inputs.NativeUserV3HookArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
final var config = ctx.config();
final var analyticsAdminPassword = config.require("analyticsAdminPassword");
var db = new Resource("db", ResourceArgs.builder()
.name("analytics-postgres")
.hostname("analytics.internal")
.technology("postgres")
.port(5432)
.nativeUsersV3Enabled(true)
.build());
// Username and password, read from an environment variable on the connector.
var basic = new NativeUserV3("basic", NativeUserV3Args.builder()
.basic(NativeUserV3BasicArgs.builder()
.password(NativeUserV3BasicPasswordArgs.builder()
.environmentVariable("ANALYTICS_ADMIN_PASSWORD")
.build())
.username("app_admin")
.build())
.resourceId(db.id())
.label("admin")
.build());
// Username and password, with the password passed as a write-only value so it
// never lands in Terraform state. Increment literal_wo_version to rotate it.
var basicWriteOnly = new NativeUserV3("basicWriteOnly", NativeUserV3Args.builder()
.basic(NativeUserV3BasicArgs.builder()
.password(NativeUserV3BasicPasswordArgs.builder()
.literalWo(analyticsAdminPassword)
.literalWoVersion(1)
.build())
.username("app_admin")
.build())
.resourceId(db.id())
.label("admin-write-only")
.build());
// AWS IAM, inheriting the role from the connector's environment.
var awsIam = new NativeUserV3("awsIam", NativeUserV3Args.builder()
.awsIam(NativeUserV3AwsIamArgs.builder()
.username("app_iam")
.build())
.resourceId(db.id())
.label("iam")
.build());
var api = new Resource("api", ResourceArgs.builder()
.name("billing-api")
.hostname("billing.internal")
.technology("http")
.port(443)
.nativeUsersV3Enabled(true)
.build());
var bearerToken = new NativeUserV3("bearerToken", NativeUserV3Args.builder()
.httpBearer(NativeUserV3HttpBearerArgs.builder()
.token(NativeUserV3HttpBearerTokenArgs.builder()
.environmentVariable("BILLING_API_TOKEN")
.build())
.header("Authorization")
.build())
.resourceId(api.id())
.label("service-account")
.build());
// Credentials resolved at connection time by a hook running on the connector,
// for example to mint short-lived credentials from a secrets manager.
var fromHook = new NativeUserV3("fromHook", NativeUserV3Args.builder()
.hook(NativeUserV3HookArgs.builder()
.outputType("basic")
.allowlistedEnvVariables(
"FORMAL_ENV_USER",
"FORMAL_ENV_PASSWORD")
.code("""
export default async function (_input, env) {
return {
username: env.FORMAL_ENV_USER,
password: env.FORMAL_ENV_PASSWORD,
};
}
""")
.build())
.resourceId(db.id())
.label("dynamic")
.build());
}
}
configuration:
analyticsAdminPassword:
type: string
resources:
db:
type: formal:Resource
properties:
name: analytics-postgres
hostname: analytics.internal
technology: postgres
port: 5432
nativeUsersV3Enabled: true
# Username and password, read from an environment variable on the connector.
basic:
type: formal:NativeUserV3
properties:
basic:
password:
environmentVariable: ANALYTICS_ADMIN_PASSWORD
username: app_admin
resourceId: ${db.id}
label: admin
# Username and password, with the password passed as a write-only value so it
# never lands in Terraform state. Increment literal_wo_version to rotate it.
basicWriteOnly:
type: formal:NativeUserV3
name: basic_write_only
properties:
basic:
password:
literalWo: ${analyticsAdminPassword}
literalWoVersion: 1
username: app_admin
resourceId: ${db.id}
label: admin-write-only
# AWS IAM, inheriting the role from the connector's environment.
awsIam:
type: formal:NativeUserV3
name: aws_iam
properties:
awsIam:
username: app_iam
resourceId: ${db.id}
label: iam
api:
type: formal:Resource
properties:
name: billing-api
hostname: billing.internal
technology: http
port: 443
nativeUsersV3Enabled: true
bearerToken:
type: formal:NativeUserV3
name: bearer_token
properties:
httpBearer:
token:
environmentVariable: BILLING_API_TOKEN
header: Authorization
resourceId: ${api.id}
label: service-account
# Credentials resolved at connection time by a hook running on the connector,
# for example to mint short-lived credentials from a secrets manager.
fromHook:
type: formal:NativeUserV3
name: from_hook
properties:
hook:
outputType: basic
allowlistedEnvVariables:
- FORMAL_ENV_USER
- FORMAL_ENV_PASSWORD
code: |
export default async function (_input, env) {
return {
username: env.FORMAL_ENV_USER,
password: env.FORMAL_ENV_PASSWORD,
};
}
resourceId: ${db.id}
label: dynamic
pulumi {
required_providers {
formal = {
source = "pulumi/formal"
}
}
}
resource "formal_resource" "db" {
name = "analytics-postgres"
hostname = "analytics.internal"
technology = "postgres"
port = 5432
native_users_v3_enabled = true
}
# Username and password, read from an environment variable on the connector.
resource "formal_nativeuserv3" "basic" {
basic = {
password = {
environment_variable = "ANALYTICS_ADMIN_PASSWORD"
}
username = "app_admin"
}
resource_id = formal_resource.db.id
label = "admin"
}
# Username and password, with the password passed as a write-only value so it
# never lands in Terraform state. Increment literal_wo_version to rotate it.
resource "formal_nativeuserv3" "basic_write_only" {
basic = {
password = {
literal_wo = var.analyticsAdminPassword
literal_wo_version = 1
}
username = "app_admin"
}
resource_id = formal_resource.db.id
label = "admin-write-only"
}
# AWS IAM, inheriting the role from the connector's environment.
resource "formal_nativeuserv3" "aws_iam" {
aws_iam = {
username = "app_iam"
}
resource_id = formal_resource.db.id
label = "iam"
}
resource "formal_resource" "api" {
name = "billing-api"
hostname = "billing.internal"
technology = "http"
port = 443
native_users_v3_enabled = true
}
resource "formal_nativeuserv3" "bearer_token" {
http_bearer = {
token = {
environment_variable = "BILLING_API_TOKEN"
}
header = "Authorization"
}
resource_id = formal_resource.api.id
label = "service-account"
}
# Credentials resolved at connection time by a hook running on the connector,
# for example to mint short-lived credentials from a secrets manager.
resource "formal_nativeuserv3" "from_hook" {
hook = {
output_type = "basic"
allowlisted_env_variables = ["FORMAL_ENV_USER", "FORMAL_ENV_PASSWORD"]
code = "export default async function (_input, env) {\n return {\n username: env.FORMAL_ENV_USER,\n password: env.FORMAL_ENV_PASSWORD,\n };\n}\n"
}
resource_id = formal_resource.db.id
label = "dynamic"
}
variable "analyticsAdminPassword" {
type = string
}
Create NativeUserV3 Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new NativeUserV3(name: string, args: NativeUserV3Args, opts?: CustomResourceOptions);@overload
def NativeUserV3(resource_name: str,
args: NativeUserV3Args,
opts: Optional[ResourceOptions] = None)
@overload
def NativeUserV3(resource_name: str,
opts: Optional[ResourceOptions] = None,
label: Optional[str] = None,
resource_id: Optional[str] = None,
gcp_iam: Optional[NativeUserV3GcpIamArgs] = None,
http_bearer: Optional[NativeUserV3HttpBearerArgs] = None,
aws_iam: Optional[NativeUserV3AwsIamArgs] = None,
hook: Optional[NativeUserV3HookArgs] = None,
http_api_key_header: Optional[NativeUserV3HttpApiKeyHeaderArgs] = None,
http_api_key_query: Optional[NativeUserV3HttpApiKeyQueryArgs] = None,
http_basic: Optional[NativeUserV3HttpBasicArgs] = None,
basic: Optional[NativeUserV3BasicArgs] = None,
kubernetes_inline: Optional[NativeUserV3KubernetesInlineArgs] = None,
kubernetes_path: Optional[NativeUserV3KubernetesPathArgs] = None,
azure_iam: Optional[NativeUserV3AzureIamArgs] = None,
aws_iam_role: Optional[NativeUserV3AwsIamRoleArgs] = None,
snowflake_key: Optional[NativeUserV3SnowflakeKeyArgs] = None,
ssh_key: Optional[NativeUserV3SshKeyArgs] = None,
termination_protection: Optional[bool] = None)func NewNativeUserV3(ctx *Context, name string, args NativeUserV3Args, opts ...ResourceOption) (*NativeUserV3, error)public NativeUserV3(string name, NativeUserV3Args args, CustomResourceOptions? opts = null)
public NativeUserV3(String name, NativeUserV3Args args)
public NativeUserV3(String name, NativeUserV3Args args, CustomResourceOptions options)
type: formal:NativeUserV3
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "formal_native_user_v3" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args NativeUserV3Args
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args NativeUserV3Args
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args NativeUserV3Args
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args NativeUserV3Args
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args NativeUserV3Args
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var nativeUserV3Resource = new Pulumi.NativeUserV3("nativeUserV3Resource", new()
{
Label = "string",
ResourceId = "string",
GcpIam = new Pulumi.Inputs.NativeUserV3GcpIamArgs
{
Username = "string",
},
HttpBearer = new Pulumi.Inputs.NativeUserV3HttpBearerArgs
{
Header = "string",
Token = new Pulumi.Inputs.NativeUserV3HttpBearerTokenArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
},
AwsIam = new Pulumi.Inputs.NativeUserV3AwsIamArgs
{
Username = "string",
},
Hook = new Pulumi.Inputs.NativeUserV3HookArgs
{
Code = "string",
OutputType = "string",
AllowlistedEnvVariables = new[]
{
"string",
},
AllowlistedNetworkHosts = new[]
{
"string",
},
},
HttpApiKeyHeader = new Pulumi.Inputs.NativeUserV3HttpApiKeyHeaderArgs
{
Key = "string",
Value = new Pulumi.Inputs.NativeUserV3HttpApiKeyHeaderValueArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
},
HttpApiKeyQuery = new Pulumi.Inputs.NativeUserV3HttpApiKeyQueryArgs
{
Key = "string",
Value = new Pulumi.Inputs.NativeUserV3HttpApiKeyQueryValueArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
},
HttpBasic = new Pulumi.Inputs.NativeUserV3HttpBasicArgs
{
Header = "string",
Password = new Pulumi.Inputs.NativeUserV3HttpBasicPasswordArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
Username = "string",
},
Basic = new Pulumi.Inputs.NativeUserV3BasicArgs
{
Password = new Pulumi.Inputs.NativeUserV3BasicPasswordArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
Username = "string",
},
KubernetesInline = new Pulumi.Inputs.NativeUserV3KubernetesInlineArgs
{
Kubeconfig = new Pulumi.Inputs.NativeUserV3KubernetesInlineKubeconfigArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
},
KubernetesPath = new Pulumi.Inputs.NativeUserV3KubernetesPathArgs
{
KubeconfigPath = new Pulumi.Inputs.NativeUserV3KubernetesPathKubeconfigPathArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
},
AzureIam = new Pulumi.Inputs.NativeUserV3AzureIamArgs
{
Username = "string",
},
AwsIamRole = new Pulumi.Inputs.NativeUserV3AwsIamRoleArgs
{
Role = "string",
Username = "string",
},
SnowflakeKey = new Pulumi.Inputs.NativeUserV3SnowflakeKeyArgs
{
Key = new Pulumi.Inputs.NativeUserV3SnowflakeKeyKeyArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
Username = "string",
},
SshKey = new Pulumi.Inputs.NativeUserV3SshKeyArgs
{
Key = new Pulumi.Inputs.NativeUserV3SshKeyKeyArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
Username = "string",
Certificate = new Pulumi.Inputs.NativeUserV3SshKeyCertificateArgs
{
EnvironmentVariable = "string",
Literal = "string",
LiteralWo = "string",
LiteralWoVersion = 0,
},
},
TerminationProtection = false,
});
example, err := formal.NewNativeUserV3(ctx, "nativeUserV3Resource", &formal.NativeUserV3Args{
Label: pulumi.String("string"),
ResourceId: pulumi.String("string"),
GcpIam: &formal.NativeUserV3GcpIamArgs{
Username: pulumi.String("string"),
},
HttpBearer: &formal.NativeUserV3HttpBearerArgs{
Header: pulumi.String("string"),
Token: &formal.NativeUserV3HttpBearerTokenArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
},
AwsIam: &formal.NativeUserV3AwsIamArgs{
Username: pulumi.String("string"),
},
Hook: &formal.NativeUserV3HookArgs{
Code: pulumi.String("string"),
OutputType: pulumi.String("string"),
AllowlistedEnvVariables: pulumi.StringArray{
pulumi.String("string"),
},
AllowlistedNetworkHosts: pulumi.StringArray{
pulumi.String("string"),
},
},
HttpApiKeyHeader: &formal.NativeUserV3HttpApiKeyHeaderArgs{
Key: pulumi.String("string"),
Value: &formal.NativeUserV3HttpApiKeyHeaderValueArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
},
HttpApiKeyQuery: &formal.NativeUserV3HttpApiKeyQueryArgs{
Key: pulumi.String("string"),
Value: &formal.NativeUserV3HttpApiKeyQueryValueArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
},
HttpBasic: &formal.NativeUserV3HttpBasicArgs{
Header: pulumi.String("string"),
Password: &formal.NativeUserV3HttpBasicPasswordArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
Username: pulumi.String("string"),
},
Basic: &formal.NativeUserV3BasicArgs{
Password: &formal.NativeUserV3BasicPasswordArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
Username: pulumi.String("string"),
},
KubernetesInline: &formal.NativeUserV3KubernetesInlineArgs{
Kubeconfig: &formal.NativeUserV3KubernetesInlineKubeconfigArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
},
KubernetesPath: &formal.NativeUserV3KubernetesPathArgs{
KubeconfigPath: &formal.NativeUserV3KubernetesPathKubeconfigPathArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
},
AzureIam: &formal.NativeUserV3AzureIamArgs{
Username: pulumi.String("string"),
},
AwsIamRole: &formal.NativeUserV3AwsIamRoleArgs{
Role: pulumi.String("string"),
Username: pulumi.String("string"),
},
SnowflakeKey: &formal.NativeUserV3SnowflakeKeyArgs{
Key: &formal.NativeUserV3SnowflakeKeyKeyArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
Username: pulumi.String("string"),
},
SshKey: &formal.NativeUserV3SshKeyArgs{
Key: &formal.NativeUserV3SshKeyKeyArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
Username: pulumi.String("string"),
Certificate: &formal.NativeUserV3SshKeyCertificateArgs{
EnvironmentVariable: pulumi.String("string"),
Literal: pulumi.String("string"),
LiteralWo: pulumi.String("string"),
LiteralWoVersion: pulumi.Int(0),
},
},
TerminationProtection: pulumi.Bool(false),
})
resource "formal_native_user_v3" "nativeUserV3Resource" {
lifecycle {
create_before_destroy = true
}
label = "string"
resource_id = "string"
gcp_iam = {
username = "string"
}
http_bearer = {
header = "string"
token = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
}
aws_iam = {
username = "string"
}
hook = {
code = "string"
output_type = "string"
allowlisted_env_variables = ["string"]
allowlisted_network_hosts = ["string"]
}
http_api_key_header = {
key = "string"
value = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
}
http_api_key_query = {
key = "string"
value = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
}
http_basic = {
header = "string"
password = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
username = "string"
}
basic = {
password = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
username = "string"
}
kubernetes_inline = {
kubeconfig = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
}
kubernetes_path = {
kubeconfig_path = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
}
azure_iam = {
username = "string"
}
aws_iam_role = {
role = "string"
username = "string"
}
snowflake_key = {
key = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
username = "string"
}
ssh_key = {
key = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
username = "string"
certificate = {
environment_variable = "string"
literal = "string"
literal_wo = "string"
literal_wo_version = 0
}
}
termination_protection = false
}
var nativeUserV3Resource = new NativeUserV3("nativeUserV3Resource", NativeUserV3Args.builder()
.label("string")
.resourceId("string")
.gcpIam(NativeUserV3GcpIamArgs.builder()
.username("string")
.build())
.httpBearer(NativeUserV3HttpBearerArgs.builder()
.header("string")
.token(NativeUserV3HttpBearerTokenArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.build())
.awsIam(NativeUserV3AwsIamArgs.builder()
.username("string")
.build())
.hook(NativeUserV3HookArgs.builder()
.code("string")
.outputType("string")
.allowlistedEnvVariables("string")
.allowlistedNetworkHosts("string")
.build())
.httpApiKeyHeader(NativeUserV3HttpApiKeyHeaderArgs.builder()
.key("string")
.value(NativeUserV3HttpApiKeyHeaderValueArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.build())
.httpApiKeyQuery(NativeUserV3HttpApiKeyQueryArgs.builder()
.key("string")
.value(NativeUserV3HttpApiKeyQueryValueArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.build())
.httpBasic(NativeUserV3HttpBasicArgs.builder()
.header("string")
.password(NativeUserV3HttpBasicPasswordArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.username("string")
.build())
.basic(NativeUserV3BasicArgs.builder()
.password(NativeUserV3BasicPasswordArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.username("string")
.build())
.kubernetesInline(NativeUserV3KubernetesInlineArgs.builder()
.kubeconfig(NativeUserV3KubernetesInlineKubeconfigArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.build())
.kubernetesPath(NativeUserV3KubernetesPathArgs.builder()
.kubeconfigPath(NativeUserV3KubernetesPathKubeconfigPathArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.build())
.azureIam(NativeUserV3AzureIamArgs.builder()
.username("string")
.build())
.awsIamRole(NativeUserV3AwsIamRoleArgs.builder()
.role("string")
.username("string")
.build())
.snowflakeKey(NativeUserV3SnowflakeKeyArgs.builder()
.key(NativeUserV3SnowflakeKeyKeyArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.username("string")
.build())
.sshKey(NativeUserV3SshKeyArgs.builder()
.key(NativeUserV3SshKeyKeyArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.username("string")
.certificate(NativeUserV3SshKeyCertificateArgs.builder()
.environmentVariable("string")
.literal("string")
.literalWo("string")
.literalWoVersion(0)
.build())
.build())
.terminationProtection(false)
.build());
native_user_v3_resource = formal.NativeUserV3("nativeUserV3Resource",
label="string",
resource_id="string",
gcp_iam={
"username": "string",
},
http_bearer={
"header": "string",
"token": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
},
aws_iam={
"username": "string",
},
hook={
"code": "string",
"output_type": "string",
"allowlisted_env_variables": ["string"],
"allowlisted_network_hosts": ["string"],
},
http_api_key_header={
"key": "string",
"value": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
},
http_api_key_query={
"key": "string",
"value": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
},
http_basic={
"header": "string",
"password": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
"username": "string",
},
basic={
"password": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
"username": "string",
},
kubernetes_inline={
"kubeconfig": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
},
kubernetes_path={
"kubeconfig_path": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
},
azure_iam={
"username": "string",
},
aws_iam_role={
"role": "string",
"username": "string",
},
snowflake_key={
"key": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
"username": "string",
},
ssh_key={
"key": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
"username": "string",
"certificate": {
"environment_variable": "string",
"literal": "string",
"literal_wo": "string",
"literal_wo_version": 0,
},
},
termination_protection=False)
const nativeUserV3Resource = new formal.NativeUserV3("nativeUserV3Resource", {
label: "string",
resourceId: "string",
gcpIam: {
username: "string",
},
httpBearer: {
header: "string",
token: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
},
awsIam: {
username: "string",
},
hook: {
code: "string",
outputType: "string",
allowlistedEnvVariables: ["string"],
allowlistedNetworkHosts: ["string"],
},
httpApiKeyHeader: {
key: "string",
value: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
},
httpApiKeyQuery: {
key: "string",
value: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
},
httpBasic: {
header: "string",
password: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
username: "string",
},
basic: {
password: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
username: "string",
},
kubernetesInline: {
kubeconfig: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
},
kubernetesPath: {
kubeconfigPath: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
},
azureIam: {
username: "string",
},
awsIamRole: {
role: "string",
username: "string",
},
snowflakeKey: {
key: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
username: "string",
},
sshKey: {
key: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
username: "string",
certificate: {
environmentVariable: "string",
literal: "string",
literalWo: "string",
literalWoVersion: 0,
},
},
terminationProtection: false,
});
type: formal:NativeUserV3
properties:
awsIam:
username: string
awsIamRole:
role: string
username: string
azureIam:
username: string
basic:
password:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
username: string
gcpIam:
username: string
hook:
allowlistedEnvVariables:
- string
allowlistedNetworkHosts:
- string
code: string
outputType: string
httpApiKeyHeader:
key: string
value:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
httpApiKeyQuery:
key: string
value:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
httpBasic:
header: string
password:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
username: string
httpBearer:
header: string
token:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
kubernetesInline:
kubeconfig:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
kubernetesPath:
kubeconfigPath:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
label: string
resourceId: string
snowflakeKey:
key:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
username: string
sshKey:
certificate:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
key:
environmentVariable: string
literal: string
literalWo: string
literalWoVersion: 0
username: string
terminationProtection: false
NativeUserV3 Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The NativeUserV3 resource accepts the following input properties:
- Label string
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- Resource
Id string - The ID of the Resource this Native User authenticates to.
- Aws
Iam Formal.Pulumi. Inputs. Native User V3Aws Iam - AWS IAM authentication.
- Aws
Iam Formal.Role Pulumi. Inputs. Native User V3Aws Iam Role - AWS IAM authentication using an assumed role.
- Azure
Iam Formal.Pulumi. Inputs. Native User V3Azure Iam - Azure IAM authentication.
- Basic
Formal.
Pulumi. Inputs. Native User V3Basic - Username and password authentication, for example Postgres or MySQL.
- Gcp
Iam Formal.Pulumi. Inputs. Native User V3Gcp Iam - GCP IAM authentication.
- Hook
Formal.
Pulumi. Inputs. Native User V3Hook - Credentials resolved on the connector by running a hook.
- Http
Api Formal.Key Header Pulumi. Inputs. Native User V3Http Api Key Header - HTTP API key authentication, sent as a header.
- Http
Api Formal.Key Query Pulumi. Inputs. Native User V3Http Api Key Query - HTTP API key authentication, sent as a query parameter.
- Http
Basic Formal.Pulumi. Inputs. Native User V3Http Basic - HTTP Basic authentication, injected on a named header.
- Http
Bearer Formal.Pulumi. Inputs. Native User V3Http Bearer - HTTP Bearer token authentication, injected on a named header.
- Kubernetes
Inline Formal.Pulumi. Inputs. Native User V3Kubernetes Inline - Kubernetes authentication using an inline kubeconfig document.
- Kubernetes
Path Formal.Pulumi. Inputs. Native User V3Kubernetes Path - Kubernetes authentication using a kubeconfig file path on the connector.
- Snowflake
Key Formal.Pulumi. Inputs. Native User V3Snowflake Key - Snowflake key-pair authentication.
- Ssh
Key Formal.Pulumi. Inputs. Native User V3Ssh Key - SSH private key authentication.
- Termination
Protection bool - If set to true, this Native User cannot be deleted.
- Label string
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- Resource
Id string - The ID of the Resource this Native User authenticates to.
- Aws
Iam NativeUser V3Aws Iam Args - AWS IAM authentication.
- Aws
Iam NativeRole User V3Aws Iam Role Args - AWS IAM authentication using an assumed role.
- Azure
Iam NativeUser V3Azure Iam Args - Azure IAM authentication.
- Basic
Native
User V3Basic Args - Username and password authentication, for example Postgres or MySQL.
- Gcp
Iam NativeUser V3Gcp Iam Args - GCP IAM authentication.
- Hook
Native
User V3Hook Args - Credentials resolved on the connector by running a hook.
- Http
Api NativeKey Header User V3Http Api Key Header Args - HTTP API key authentication, sent as a header.
- Http
Api NativeKey Query User V3Http Api Key Query Args - HTTP API key authentication, sent as a query parameter.
- Http
Basic NativeUser V3Http Basic Args - HTTP Basic authentication, injected on a named header.
- Http
Bearer NativeUser V3Http Bearer Args - HTTP Bearer token authentication, injected on a named header.
- Kubernetes
Inline NativeUser V3Kubernetes Inline Args - Kubernetes authentication using an inline kubeconfig document.
- Kubernetes
Path NativeUser V3Kubernetes Path Args - Kubernetes authentication using a kubeconfig file path on the connector.
- Snowflake
Key NativeUser V3Snowflake Key Args - Snowflake key-pair authentication.
- Ssh
Key NativeUser V3Ssh Key Args - SSH private key authentication.
- Termination
Protection bool - If set to true, this Native User cannot be deleted.
- label string
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource_
id string - The ID of the Resource this Native User authenticates to.
- aws_
iam object - AWS IAM authentication.
- aws_
iam_ objectrole - AWS IAM authentication using an assumed role.
- azure_
iam object - Azure IAM authentication.
- basic object
- Username and password authentication, for example Postgres or MySQL.
- gcp_
iam object - GCP IAM authentication.
- hook object
- Credentials resolved on the connector by running a hook.
- http_
api_ objectkey_ header - HTTP API key authentication, sent as a header.
- http_
api_ objectkey_ query - HTTP API key authentication, sent as a query parameter.
- http_
basic object - HTTP Basic authentication, injected on a named header.
- http_
bearer object - HTTP Bearer token authentication, injected on a named header.
- kubernetes_
inline object - Kubernetes authentication using an inline kubeconfig document.
- kubernetes_
path object - Kubernetes authentication using a kubeconfig file path on the connector.
- snowflake_
key object - Snowflake key-pair authentication.
- ssh_
key object - SSH private key authentication.
- termination_
protection bool - If set to true, this Native User cannot be deleted.
- label String
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource
Id String - The ID of the Resource this Native User authenticates to.
- aws
Iam NativeUser V3Aws Iam - AWS IAM authentication.
- aws
Iam NativeRole User V3Aws Iam Role - AWS IAM authentication using an assumed role.
- azure
Iam NativeUser V3Azure Iam - Azure IAM authentication.
- basic
Native
User V3Basic - Username and password authentication, for example Postgres or MySQL.
- gcp
Iam NativeUser V3Gcp Iam - GCP IAM authentication.
- hook
Native
User V3Hook - Credentials resolved on the connector by running a hook.
- http
Api NativeKey Header User V3Http Api Key Header - HTTP API key authentication, sent as a header.
- http
Api NativeKey Query User V3Http Api Key Query - HTTP API key authentication, sent as a query parameter.
- http
Basic NativeUser V3Http Basic - HTTP Basic authentication, injected on a named header.
- http
Bearer NativeUser V3Http Bearer - HTTP Bearer token authentication, injected on a named header.
- kubernetes
Inline NativeUser V3Kubernetes Inline - Kubernetes authentication using an inline kubeconfig document.
- kubernetes
Path NativeUser V3Kubernetes Path - Kubernetes authentication using a kubeconfig file path on the connector.
- snowflake
Key NativeUser V3Snowflake Key - Snowflake key-pair authentication.
- ssh
Key NativeUser V3Ssh Key - SSH private key authentication.
- termination
Protection Boolean - If set to true, this Native User cannot be deleted.
- label string
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource
Id string - The ID of the Resource this Native User authenticates to.
- aws
Iam NativeUser V3Aws Iam - AWS IAM authentication.
- aws
Iam NativeRole User V3Aws Iam Role - AWS IAM authentication using an assumed role.
- azure
Iam NativeUser V3Azure Iam - Azure IAM authentication.
- basic
Native
User V3Basic - Username and password authentication, for example Postgres or MySQL.
- gcp
Iam NativeUser V3Gcp Iam - GCP IAM authentication.
- hook
Native
User V3Hook - Credentials resolved on the connector by running a hook.
- http
Api NativeKey Header User V3Http Api Key Header - HTTP API key authentication, sent as a header.
- http
Api NativeKey Query User V3Http Api Key Query - HTTP API key authentication, sent as a query parameter.
- http
Basic NativeUser V3Http Basic - HTTP Basic authentication, injected on a named header.
- http
Bearer NativeUser V3Http Bearer - HTTP Bearer token authentication, injected on a named header.
- kubernetes
Inline NativeUser V3Kubernetes Inline - Kubernetes authentication using an inline kubeconfig document.
- kubernetes
Path NativeUser V3Kubernetes Path - Kubernetes authentication using a kubeconfig file path on the connector.
- snowflake
Key NativeUser V3Snowflake Key - Snowflake key-pair authentication.
- ssh
Key NativeUser V3Ssh Key - SSH private key authentication.
- termination
Protection boolean - If set to true, this Native User cannot be deleted.
- label str
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource_
id str - The ID of the Resource this Native User authenticates to.
- aws_
iam NativeUser V3Aws Iam Args - AWS IAM authentication.
- aws_
iam_ Nativerole User V3Aws Iam Role Args - AWS IAM authentication using an assumed role.
- azure_
iam NativeUser V3Azure Iam Args - Azure IAM authentication.
- basic
Native
User V3Basic Args - Username and password authentication, for example Postgres or MySQL.
- gcp_
iam NativeUser V3Gcp Iam Args - GCP IAM authentication.
- hook
Native
User V3Hook Args - Credentials resolved on the connector by running a hook.
- http_
api_ Nativekey_ header User V3Http Api Key Header Args - HTTP API key authentication, sent as a header.
- http_
api_ Nativekey_ query User V3Http Api Key Query Args - HTTP API key authentication, sent as a query parameter.
- http_
basic NativeUser V3Http Basic Args - HTTP Basic authentication, injected on a named header.
- http_
bearer NativeUser V3Http Bearer Args - HTTP Bearer token authentication, injected on a named header.
- kubernetes_
inline NativeUser V3Kubernetes Inline Args - Kubernetes authentication using an inline kubeconfig document.
- kubernetes_
path NativeUser V3Kubernetes Path Args - Kubernetes authentication using a kubeconfig file path on the connector.
- snowflake_
key NativeUser V3Snowflake Key Args - Snowflake key-pair authentication.
- ssh_
key NativeUser V3Ssh Key Args - SSH private key authentication.
- termination_
protection bool - If set to true, this Native User cannot be deleted.
- label String
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource
Id String - The ID of the Resource this Native User authenticates to.
- aws
Iam Property Map - AWS IAM authentication.
- aws
Iam Property MapRole - AWS IAM authentication using an assumed role.
- azure
Iam Property Map - Azure IAM authentication.
- basic Property Map
- Username and password authentication, for example Postgres or MySQL.
- gcp
Iam Property Map - GCP IAM authentication.
- hook Property Map
- Credentials resolved on the connector by running a hook.
- http
Api Property MapKey Header - HTTP API key authentication, sent as a header.
- http
Api Property MapKey Query - HTTP API key authentication, sent as a query parameter.
- http
Basic Property Map - HTTP Basic authentication, injected on a named header.
- http
Bearer Property Map - HTTP Bearer token authentication, injected on a named header.
- kubernetes
Inline Property Map - Kubernetes authentication using an inline kubeconfig document.
- kubernetes
Path Property Map - Kubernetes authentication using a kubeconfig file path on the connector.
- snowflake
Key Property Map - Snowflake key-pair authentication.
- ssh
Key Property Map - SSH private key authentication.
- termination
Protection Boolean - If set to true, this Native User cannot be deleted.
Outputs
All input properties are implicitly available as output properties. Additionally, the NativeUserV3 resource produces the following output properties:
- created_
at string - Creation time of the Native User.
- id string
- The provider-assigned unique ID for this managed resource.
- updated_
at string - Last update time of the Native User.
- created_
at str - Creation time of the Native User.
- id str
- The provider-assigned unique ID for this managed resource.
- updated_
at str - Last update time of the Native User.
Look up Existing NativeUserV3 Resource
Get an existing NativeUserV3 resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: NativeUserV3State, opts?: CustomResourceOptions): NativeUserV3@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
aws_iam: Optional[NativeUserV3AwsIamArgs] = None,
aws_iam_role: Optional[NativeUserV3AwsIamRoleArgs] = None,
azure_iam: Optional[NativeUserV3AzureIamArgs] = None,
basic: Optional[NativeUserV3BasicArgs] = None,
created_at: Optional[str] = None,
gcp_iam: Optional[NativeUserV3GcpIamArgs] = None,
hook: Optional[NativeUserV3HookArgs] = None,
http_api_key_header: Optional[NativeUserV3HttpApiKeyHeaderArgs] = None,
http_api_key_query: Optional[NativeUserV3HttpApiKeyQueryArgs] = None,
http_basic: Optional[NativeUserV3HttpBasicArgs] = None,
http_bearer: Optional[NativeUserV3HttpBearerArgs] = None,
kubernetes_inline: Optional[NativeUserV3KubernetesInlineArgs] = None,
kubernetes_path: Optional[NativeUserV3KubernetesPathArgs] = None,
label: Optional[str] = None,
resource_id: Optional[str] = None,
snowflake_key: Optional[NativeUserV3SnowflakeKeyArgs] = None,
ssh_key: Optional[NativeUserV3SshKeyArgs] = None,
termination_protection: Optional[bool] = None,
updated_at: Optional[str] = None) -> NativeUserV3func GetNativeUserV3(ctx *Context, name string, id IDInput, state *NativeUserV3State, opts ...ResourceOption) (*NativeUserV3, error)public static NativeUserV3 Get(string name, Input<string> id, NativeUserV3State? state, CustomResourceOptions? opts = null)public static NativeUserV3 get(String name, Output<String> id, NativeUserV3State state, CustomResourceOptions options)resources: _: type: formal:NativeUserV3 get: id: ${id}import {
to = formal_native_user_v3.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Aws
Iam Formal.Pulumi. Inputs. Native User V3Aws Iam - AWS IAM authentication.
- Aws
Iam Formal.Role Pulumi. Inputs. Native User V3Aws Iam Role - AWS IAM authentication using an assumed role.
- Azure
Iam Formal.Pulumi. Inputs. Native User V3Azure Iam - Azure IAM authentication.
- Basic
Formal.
Pulumi. Inputs. Native User V3Basic - Username and password authentication, for example Postgres or MySQL.
- Created
At string - Creation time of the Native User.
- Gcp
Iam Formal.Pulumi. Inputs. Native User V3Gcp Iam - GCP IAM authentication.
- Hook
Formal.
Pulumi. Inputs. Native User V3Hook - Credentials resolved on the connector by running a hook.
- Http
Api Formal.Key Header Pulumi. Inputs. Native User V3Http Api Key Header - HTTP API key authentication, sent as a header.
- Http
Api Formal.Key Query Pulumi. Inputs. Native User V3Http Api Key Query - HTTP API key authentication, sent as a query parameter.
- Http
Basic Formal.Pulumi. Inputs. Native User V3Http Basic - HTTP Basic authentication, injected on a named header.
- Http
Bearer Formal.Pulumi. Inputs. Native User V3Http Bearer - HTTP Bearer token authentication, injected on a named header.
- Kubernetes
Inline Formal.Pulumi. Inputs. Native User V3Kubernetes Inline - Kubernetes authentication using an inline kubeconfig document.
- Kubernetes
Path Formal.Pulumi. Inputs. Native User V3Kubernetes Path - Kubernetes authentication using a kubeconfig file path on the connector.
- Label string
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- Resource
Id string - The ID of the Resource this Native User authenticates to.
- Snowflake
Key Formal.Pulumi. Inputs. Native User V3Snowflake Key - Snowflake key-pair authentication.
- Ssh
Key Formal.Pulumi. Inputs. Native User V3Ssh Key - SSH private key authentication.
- Termination
Protection bool - If set to true, this Native User cannot be deleted.
- Updated
At string - Last update time of the Native User.
- Aws
Iam NativeUser V3Aws Iam Args - AWS IAM authentication.
- Aws
Iam NativeRole User V3Aws Iam Role Args - AWS IAM authentication using an assumed role.
- Azure
Iam NativeUser V3Azure Iam Args - Azure IAM authentication.
- Basic
Native
User V3Basic Args - Username and password authentication, for example Postgres or MySQL.
- Created
At string - Creation time of the Native User.
- Gcp
Iam NativeUser V3Gcp Iam Args - GCP IAM authentication.
- Hook
Native
User V3Hook Args - Credentials resolved on the connector by running a hook.
- Http
Api NativeKey Header User V3Http Api Key Header Args - HTTP API key authentication, sent as a header.
- Http
Api NativeKey Query User V3Http Api Key Query Args - HTTP API key authentication, sent as a query parameter.
- Http
Basic NativeUser V3Http Basic Args - HTTP Basic authentication, injected on a named header.
- Http
Bearer NativeUser V3Http Bearer Args - HTTP Bearer token authentication, injected on a named header.
- Kubernetes
Inline NativeUser V3Kubernetes Inline Args - Kubernetes authentication using an inline kubeconfig document.
- Kubernetes
Path NativeUser V3Kubernetes Path Args - Kubernetes authentication using a kubeconfig file path on the connector.
- Label string
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- Resource
Id string - The ID of the Resource this Native User authenticates to.
- Snowflake
Key NativeUser V3Snowflake Key Args - Snowflake key-pair authentication.
- Ssh
Key NativeUser V3Ssh Key Args - SSH private key authentication.
- Termination
Protection bool - If set to true, this Native User cannot be deleted.
- Updated
At string - Last update time of the Native User.
- aws_
iam object - AWS IAM authentication.
- aws_
iam_ objectrole - AWS IAM authentication using an assumed role.
- azure_
iam object - Azure IAM authentication.
- basic object
- Username and password authentication, for example Postgres or MySQL.
- created_
at string - Creation time of the Native User.
- gcp_
iam object - GCP IAM authentication.
- hook object
- Credentials resolved on the connector by running a hook.
- http_
api_ objectkey_ header - HTTP API key authentication, sent as a header.
- http_
api_ objectkey_ query - HTTP API key authentication, sent as a query parameter.
- http_
basic object - HTTP Basic authentication, injected on a named header.
- http_
bearer object - HTTP Bearer token authentication, injected on a named header.
- kubernetes_
inline object - Kubernetes authentication using an inline kubeconfig document.
- kubernetes_
path object - Kubernetes authentication using a kubeconfig file path on the connector.
- label string
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource_
id string - The ID of the Resource this Native User authenticates to.
- snowflake_
key object - Snowflake key-pair authentication.
- ssh_
key object - SSH private key authentication.
- termination_
protection bool - If set to true, this Native User cannot be deleted.
- updated_
at string - Last update time of the Native User.
- aws
Iam NativeUser V3Aws Iam - AWS IAM authentication.
- aws
Iam NativeRole User V3Aws Iam Role - AWS IAM authentication using an assumed role.
- azure
Iam NativeUser V3Azure Iam - Azure IAM authentication.
- basic
Native
User V3Basic - Username and password authentication, for example Postgres or MySQL.
- created
At String - Creation time of the Native User.
- gcp
Iam NativeUser V3Gcp Iam - GCP IAM authentication.
- hook
Native
User V3Hook - Credentials resolved on the connector by running a hook.
- http
Api NativeKey Header User V3Http Api Key Header - HTTP API key authentication, sent as a header.
- http
Api NativeKey Query User V3Http Api Key Query - HTTP API key authentication, sent as a query parameter.
- http
Basic NativeUser V3Http Basic - HTTP Basic authentication, injected on a named header.
- http
Bearer NativeUser V3Http Bearer - HTTP Bearer token authentication, injected on a named header.
- kubernetes
Inline NativeUser V3Kubernetes Inline - Kubernetes authentication using an inline kubeconfig document.
- kubernetes
Path NativeUser V3Kubernetes Path - Kubernetes authentication using a kubeconfig file path on the connector.
- label String
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource
Id String - The ID of the Resource this Native User authenticates to.
- snowflake
Key NativeUser V3Snowflake Key - Snowflake key-pair authentication.
- ssh
Key NativeUser V3Ssh Key - SSH private key authentication.
- termination
Protection Boolean - If set to true, this Native User cannot be deleted.
- updated
At String - Last update time of the Native User.
- aws
Iam NativeUser V3Aws Iam - AWS IAM authentication.
- aws
Iam NativeRole User V3Aws Iam Role - AWS IAM authentication using an assumed role.
- azure
Iam NativeUser V3Azure Iam - Azure IAM authentication.
- basic
Native
User V3Basic - Username and password authentication, for example Postgres or MySQL.
- created
At string - Creation time of the Native User.
- gcp
Iam NativeUser V3Gcp Iam - GCP IAM authentication.
- hook
Native
User V3Hook - Credentials resolved on the connector by running a hook.
- http
Api NativeKey Header User V3Http Api Key Header - HTTP API key authentication, sent as a header.
- http
Api NativeKey Query User V3Http Api Key Query - HTTP API key authentication, sent as a query parameter.
- http
Basic NativeUser V3Http Basic - HTTP Basic authentication, injected on a named header.
- http
Bearer NativeUser V3Http Bearer - HTTP Bearer token authentication, injected on a named header.
- kubernetes
Inline NativeUser V3Kubernetes Inline - Kubernetes authentication using an inline kubeconfig document.
- kubernetes
Path NativeUser V3Kubernetes Path - Kubernetes authentication using a kubeconfig file path on the connector.
- label string
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource
Id string - The ID of the Resource this Native User authenticates to.
- snowflake
Key NativeUser V3Snowflake Key - Snowflake key-pair authentication.
- ssh
Key NativeUser V3Ssh Key - SSH private key authentication.
- termination
Protection boolean - If set to true, this Native User cannot be deleted.
- updated
At string - Last update time of the Native User.
- aws_
iam NativeUser V3Aws Iam Args - AWS IAM authentication.
- aws_
iam_ Nativerole User V3Aws Iam Role Args - AWS IAM authentication using an assumed role.
- azure_
iam NativeUser V3Azure Iam Args - Azure IAM authentication.
- basic
Native
User V3Basic Args - Username and password authentication, for example Postgres or MySQL.
- created_
at str - Creation time of the Native User.
- gcp_
iam NativeUser V3Gcp Iam Args - GCP IAM authentication.
- hook
Native
User V3Hook Args - Credentials resolved on the connector by running a hook.
- http_
api_ Nativekey_ header User V3Http Api Key Header Args - HTTP API key authentication, sent as a header.
- http_
api_ Nativekey_ query User V3Http Api Key Query Args - HTTP API key authentication, sent as a query parameter.
- http_
basic NativeUser V3Http Basic Args - HTTP Basic authentication, injected on a named header.
- http_
bearer NativeUser V3Http Bearer Args - HTTP Bearer token authentication, injected on a named header.
- kubernetes_
inline NativeUser V3Kubernetes Inline Args - Kubernetes authentication using an inline kubeconfig document.
- kubernetes_
path NativeUser V3Kubernetes Path Args - Kubernetes authentication using a kubeconfig file path on the connector.
- label str
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource_
id str - The ID of the Resource this Native User authenticates to.
- snowflake_
key NativeUser V3Snowflake Key Args - Snowflake key-pair authentication.
- ssh_
key NativeUser V3Ssh Key Args - SSH private key authentication.
- termination_
protection bool - If set to true, this Native User cannot be deleted.
- updated_
at str - Last update time of the Native User.
- aws
Iam Property Map - AWS IAM authentication.
- aws
Iam Property MapRole - AWS IAM authentication using an assumed role.
- azure
Iam Property Map - Azure IAM authentication.
- basic Property Map
- Username and password authentication, for example Postgres or MySQL.
- created
At String - Creation time of the Native User.
- gcp
Iam Property Map - GCP IAM authentication.
- hook Property Map
- Credentials resolved on the connector by running a hook.
- http
Api Property MapKey Header - HTTP API key authentication, sent as a header.
- http
Api Property MapKey Query - HTTP API key authentication, sent as a query parameter.
- http
Basic Property Map - HTTP Basic authentication, injected on a named header.
- http
Bearer Property Map - HTTP Bearer token authentication, injected on a named header.
- kubernetes
Inline Property Map - Kubernetes authentication using an inline kubeconfig document.
- kubernetes
Path Property Map - Kubernetes authentication using a kubeconfig file path on the connector.
- label String
- A name for this Native User, unique within the Resource. Selection expressions reference the Native User by ID, so the label is safe to rename.
- resource
Id String - The ID of the Resource this Native User authenticates to.
- snowflake
Key Property Map - Snowflake key-pair authentication.
- ssh
Key Property Map - SSH private key authentication.
- termination
Protection Boolean - If set to true, this Native User cannot be deleted.
- updated
At String - Last update time of the Native User.
Supporting Types
NativeUserV3AwsIam, NativeUserV3AwsIamArgs
- Username string
- The database username mapped to the IAM identity.
- Username string
- The database username mapped to the IAM identity.
- username string
- The database username mapped to the IAM identity.
- username String
- The database username mapped to the IAM identity.
- username string
- The database username mapped to the IAM identity.
- username str
- The database username mapped to the IAM identity.
- username String
- The database username mapped to the IAM identity.
NativeUserV3AwsIamRole, NativeUserV3AwsIamRoleArgs
NativeUserV3AzureIam, NativeUserV3AzureIamArgs
- Username string
- The database username mapped to the Azure identity.
- Username string
- The database username mapped to the Azure identity.
- username string
- The database username mapped to the Azure identity.
- username String
- The database username mapped to the Azure identity.
- username string
- The database username mapped to the Azure identity.
- username str
- The database username mapped to the Azure identity.
- username String
- The database username mapped to the Azure identity.
NativeUserV3Basic, NativeUserV3BasicArgs
- Password
Formal.
Pulumi. Inputs. Native User V3Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - Username string
- The username to authenticate as.
- Password
Native
User V3Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - Username string
- The username to authenticate as.
- password
Native
User V3Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - username String
- The username to authenticate as.
- password
Native
User V3Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - username string
- The username to authenticate as.
- password
Native
User V3Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - username str
- The username to authenticate as.
- password Property Map
- The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - username String
- The username to authenticate as.
NativeUserV3BasicPassword, NativeUserV3BasicPasswordArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3GcpIam, NativeUserV3GcpIamArgs
- Username string
- The database username mapped to the GCP identity.
- Username string
- The database username mapped to the GCP identity.
- username string
- The database username mapped to the GCP identity.
- username String
- The database username mapped to the GCP identity.
- username string
- The database username mapped to the GCP identity.
- username str
- The database username mapped to the GCP identity.
- username String
- The database username mapped to the GCP identity.
NativeUserV3Hook, NativeUserV3HookArgs
- Code string
- The TypeScript or JavaScript source of the hook, in the same form as
formal_hook.code. - Output
Type string - The credential shape the hook must return, so the connector can validate its result. One of:
basic,awsIam,awsIamRole,gcpIam,azureIam,kubernetesPath,kubernetesInline,sshKey,snowflakeKey,httpBasic,httpBearer,httpApiKeyHeader,httpApiKeyQuery. - Allowlisted
Env List<string>Variables - Environment variables the hook may read.
- Allowlisted
Network List<string>Hosts - Network hosts the hook may access.
- Code string
- The TypeScript or JavaScript source of the hook, in the same form as
formal_hook.code. - Output
Type string - The credential shape the hook must return, so the connector can validate its result. One of:
basic,awsIam,awsIamRole,gcpIam,azureIam,kubernetesPath,kubernetesInline,sshKey,snowflakeKey,httpBasic,httpBearer,httpApiKeyHeader,httpApiKeyQuery. - Allowlisted
Env []stringVariables - Environment variables the hook may read.
- Allowlisted
Network []stringHosts - Network hosts the hook may access.
- code string
- The TypeScript or JavaScript source of the hook, in the same form as
formal_hook.code. - output_
type string - The credential shape the hook must return, so the connector can validate its result. One of:
basic,awsIam,awsIamRole,gcpIam,azureIam,kubernetesPath,kubernetesInline,sshKey,snowflakeKey,httpBasic,httpBearer,httpApiKeyHeader,httpApiKeyQuery. - allowlisted_
env_ list(string)variables - Environment variables the hook may read.
- allowlisted_
network_ list(string)hosts - Network hosts the hook may access.
- code String
- The TypeScript or JavaScript source of the hook, in the same form as
formal_hook.code. - output
Type String - The credential shape the hook must return, so the connector can validate its result. One of:
basic,awsIam,awsIamRole,gcpIam,azureIam,kubernetesPath,kubernetesInline,sshKey,snowflakeKey,httpBasic,httpBearer,httpApiKeyHeader,httpApiKeyQuery. - allowlisted
Env List<String>Variables - Environment variables the hook may read.
- allowlisted
Network List<String>Hosts - Network hosts the hook may access.
- code string
- The TypeScript or JavaScript source of the hook, in the same form as
formal_hook.code. - output
Type string - The credential shape the hook must return, so the connector can validate its result. One of:
basic,awsIam,awsIamRole,gcpIam,azureIam,kubernetesPath,kubernetesInline,sshKey,snowflakeKey,httpBasic,httpBearer,httpApiKeyHeader,httpApiKeyQuery. - allowlisted
Env string[]Variables - Environment variables the hook may read.
- allowlisted
Network string[]Hosts - Network hosts the hook may access.
- code str
- The TypeScript or JavaScript source of the hook, in the same form as
formal_hook.code. - output_
type str - The credential shape the hook must return, so the connector can validate its result. One of:
basic,awsIam,awsIamRole,gcpIam,azureIam,kubernetesPath,kubernetesInline,sshKey,snowflakeKey,httpBasic,httpBearer,httpApiKeyHeader,httpApiKeyQuery. - allowlisted_
env_ Sequence[str]variables - Environment variables the hook may read.
- allowlisted_
network_ Sequence[str]hosts - Network hosts the hook may access.
- code String
- The TypeScript or JavaScript source of the hook, in the same form as
formal_hook.code. - output
Type String - The credential shape the hook must return, so the connector can validate its result. One of:
basic,awsIam,awsIamRole,gcpIam,azureIam,kubernetesPath,kubernetesInline,sshKey,snowflakeKey,httpBasic,httpBearer,httpApiKeyHeader,httpApiKeyQuery. - allowlisted
Env List<String>Variables - Environment variables the hook may read.
- allowlisted
Network List<String>Hosts - Network hosts the hook may access.
NativeUserV3HttpApiKeyHeader, NativeUserV3HttpApiKeyHeaderArgs
- Key string
- The name of the header carrying the API key.
- Value
Formal.
Pulumi. Inputs. Native User V3Http Api Key Header Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- Key string
- The name of the header carrying the API key.
- Value
Native
User V3Http Api Key Header Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key String
- The name of the header carrying the API key.
- value
Native
User V3Http Api Key Header Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key string
- The name of the header carrying the API key.
- value
Native
User V3Http Api Key Header Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key str
- The name of the header carrying the API key.
- value
Native
User V3Http Api Key Header Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key String
- The name of the header carrying the API key.
- value Property Map
- The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
NativeUserV3HttpApiKeyHeaderValue, NativeUserV3HttpApiKeyHeaderValueArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3HttpApiKeyQuery, NativeUserV3HttpApiKeyQueryArgs
- Key string
- The name of the query parameter carrying the API key.
- Value
Formal.
Pulumi. Inputs. Native User V3Http Api Key Query Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- Key string
- The name of the query parameter carrying the API key.
- Value
Native
User V3Http Api Key Query Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key String
- The name of the query parameter carrying the API key.
- value
Native
User V3Http Api Key Query Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key string
- The name of the query parameter carrying the API key.
- value
Native
User V3Http Api Key Query Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key str
- The name of the query parameter carrying the API key.
- value
Native
User V3Http Api Key Query Value - The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key String
- The name of the query parameter carrying the API key.
- value Property Map
- The API key. Set exactly one of
literal,literalWoorenvironmentVariable.
NativeUserV3HttpApiKeyQueryValue, NativeUserV3HttpApiKeyQueryValueArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3HttpBasic, NativeUserV3HttpBasicArgs
- Header string
- The header to inject the credentials on, for example
Authorization. - Password
Formal.
Pulumi. Inputs. Native User V3Http Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - Username string
- The username to authenticate as.
- Header string
- The header to inject the credentials on, for example
Authorization. - Password
Native
User V3Http Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - Username string
- The username to authenticate as.
- header String
- The header to inject the credentials on, for example
Authorization. - password
Native
User V3Http Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - username String
- The username to authenticate as.
- header string
- The header to inject the credentials on, for example
Authorization. - password
Native
User V3Http Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - username string
- The username to authenticate as.
- header str
- The header to inject the credentials on, for example
Authorization. - password
Native
User V3Http Basic Password - The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - username str
- The username to authenticate as.
- header String
- The header to inject the credentials on, for example
Authorization. - password Property Map
- The password to authenticate with. Set exactly one of
literal,literalWoorenvironmentVariable. - username String
- The username to authenticate as.
NativeUserV3HttpBasicPassword, NativeUserV3HttpBasicPasswordArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3HttpBearer, NativeUserV3HttpBearerArgs
- Header string
- The header to inject the token on, for example
Authorization. - Token
Formal.
Pulumi. Inputs. Native User V3Http Bearer Token - The bearer token. Set exactly one of
literal,literalWoorenvironmentVariable.
- Header string
- The header to inject the token on, for example
Authorization. - Token
Native
User V3Http Bearer Token - The bearer token. Set exactly one of
literal,literalWoorenvironmentVariable.
- header String
- The header to inject the token on, for example
Authorization. - token
Native
User V3Http Bearer Token - The bearer token. Set exactly one of
literal,literalWoorenvironmentVariable.
- header string
- The header to inject the token on, for example
Authorization. - token
Native
User V3Http Bearer Token - The bearer token. Set exactly one of
literal,literalWoorenvironmentVariable.
- header str
- The header to inject the token on, for example
Authorization. - token
Native
User V3Http Bearer Token - The bearer token. Set exactly one of
literal,literalWoorenvironmentVariable.
- header String
- The header to inject the token on, for example
Authorization. - token Property Map
- The bearer token. Set exactly one of
literal,literalWoorenvironmentVariable.
NativeUserV3HttpBearerToken, NativeUserV3HttpBearerTokenArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3KubernetesInline, NativeUserV3KubernetesInlineArgs
- Kubeconfig
Formal.
Pulumi. Inputs. Native User V3Kubernetes Inline Kubeconfig - The kubeconfig YAML document. Set exactly one of
literal,literalWoorenvironmentVariable.
- Kubeconfig
Native
User V3Kubernetes Inline Kubeconfig - The kubeconfig YAML document. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig object
- The kubeconfig YAML document. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig
Native
User V3Kubernetes Inline Kubeconfig - The kubeconfig YAML document. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig
Native
User V3Kubernetes Inline Kubeconfig - The kubeconfig YAML document. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig
Native
User V3Kubernetes Inline Kubeconfig - The kubeconfig YAML document. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig Property Map
- The kubeconfig YAML document. Set exactly one of
literal,literalWoorenvironmentVariable.
NativeUserV3KubernetesInlineKubeconfig, NativeUserV3KubernetesInlineKubeconfigArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3KubernetesPath, NativeUserV3KubernetesPathArgs
- Kubeconfig
Path Formal.Pulumi. Inputs. Native User V3Kubernetes Path Kubeconfig Path - Path to the kubeconfig file on the connector. Set exactly one of
literal,literalWoorenvironmentVariable.
- Kubeconfig
Path NativeUser V3Kubernetes Path Kubeconfig Path - Path to the kubeconfig file on the connector. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig_
path object - Path to the kubeconfig file on the connector. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig
Path NativeUser V3Kubernetes Path Kubeconfig Path - Path to the kubeconfig file on the connector. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig
Path NativeUser V3Kubernetes Path Kubeconfig Path - Path to the kubeconfig file on the connector. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig_
path NativeUser V3Kubernetes Path Kubeconfig Path - Path to the kubeconfig file on the connector. Set exactly one of
literal,literalWoorenvironmentVariable.
- kubeconfig
Path Property Map - Path to the kubeconfig file on the connector. Set exactly one of
literal,literalWoorenvironmentVariable.
NativeUserV3KubernetesPathKubeconfigPath, NativeUserV3KubernetesPathKubeconfigPathArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3SnowflakeKey, NativeUserV3SnowflakeKeyArgs
- Key
Formal.
Pulumi. Inputs. Native User V3Snowflake Key Key - The private key. Set exactly one of
literal,literalWoorenvironmentVariable. - Username string
- The Snowflake username to authenticate as.
- Key
Native
User V3Snowflake Key Key - The private key. Set exactly one of
literal,literalWoorenvironmentVariable. - Username string
- The Snowflake username to authenticate as.
- key
Native
User V3Snowflake Key Key - The private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username String
- The Snowflake username to authenticate as.
- key
Native
User V3Snowflake Key Key - The private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username string
- The Snowflake username to authenticate as.
- key
Native
User V3Snowflake Key Key - The private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username str
- The Snowflake username to authenticate as.
- key Property Map
- The private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username String
- The Snowflake username to authenticate as.
NativeUserV3SnowflakeKeyKey, NativeUserV3SnowflakeKeyKeyArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3SshKey, NativeUserV3SshKeyArgs
- Key
Formal.
Pulumi. Inputs. Native User V3Ssh Key Key - The SSH private key. Set exactly one of
literal,literalWoorenvironmentVariable. - Username string
- The username to authenticate as.
- Certificate
Formal.
Pulumi. Inputs. Native User V3Ssh Key Certificate - The optional SSH certificate paired with the private key. Set exactly one of
literal,literalWoorenvironmentVariable.
- Key
Native
User V3Ssh Key Key - The SSH private key. Set exactly one of
literal,literalWoorenvironmentVariable. - Username string
- The username to authenticate as.
- Certificate
Native
User V3Ssh Key Certificate - The optional SSH certificate paired with the private key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key object
- The SSH private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username string
- The username to authenticate as.
- certificate object
- The optional SSH certificate paired with the private key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key
Native
User V3Ssh Key Key - The SSH private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username String
- The username to authenticate as.
- certificate
Native
User V3Ssh Key Certificate - The optional SSH certificate paired with the private key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key
Native
User V3Ssh Key Key - The SSH private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username string
- The username to authenticate as.
- certificate
Native
User V3Ssh Key Certificate - The optional SSH certificate paired with the private key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key
Native
User V3Ssh Key Key - The SSH private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username str
- The username to authenticate as.
- certificate
Native
User V3Ssh Key Certificate - The optional SSH certificate paired with the private key. Set exactly one of
literal,literalWoorenvironmentVariable.
- key Property Map
- The SSH private key. Set exactly one of
literal,literalWoorenvironmentVariable. - username String
- The username to authenticate as.
- certificate Property Map
- The optional SSH certificate paired with the private key. Set exactly one of
literal,literalWoorenvironmentVariable.
NativeUserV3SshKeyCertificate, NativeUserV3SshKeyCertificateArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
NativeUserV3SshKeyKey, NativeUserV3SshKeyKeyArgs
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- Environment
Variable string - The name of an environment variable the connector reads the secret from.
- Literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - Literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - Literal
Wo intVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ numberversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo IntegerVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable string - The name of an environment variable the connector reads the secret from.
- literal string
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo string - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo numberVersion - Version trigger for
literalWo. Increment this value to update the secret.
- environment_
variable str - The name of an environment variable the connector reads the secret from.
- literal str
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal_
wo str - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal_
wo_ intversion - Version trigger for
literalWo. Increment this value to update the secret.
- environment
Variable String - The name of an environment variable the connector reads the secret from.
- literal String
- The secret value itself. Stored in Terraform state; prefer
literalWoorenvironmentVariablewhere possible. - literal
Wo String - NOTE: This field is write-only and its value will not be updated in state as part of read operations.
Write-only secret value. This value is not stored in Terraform state, so it must stay in the configuration: any later change to this credential resends it. Requires Terraform 1.11+ and
literalWoVersion. - literal
Wo NumberVersion - Version trigger for
literalWo. Increment this value to update the secret.
Package Details
- Repository
- formal formalco/pulumi-formal
- License
- MPL-2.0
- Notes
- This Pulumi package is based on the
formalTerraform Provider.
published on Monday, Sep 21, 2026 by Formal