1. Registry
  2. Packages
  3. Kurrent Cloud
  4. Installation & Configuration
Viewing docs for Kurrent Cloud v0.3.1
published on Tuesday, Oct 6, 2026 by Kurrent

Kurrent Cloud: Installation & Configuration

kurrentcloud logo Kurrent Cloud
Viewing docs for Kurrent Cloud v0.3.1
published on Tuesday, Oct 6, 2026 by Kurrent

    Installation

    The Kurrent Cloud provider is available as a package in all Pulumi languages:

    Setup

    Configure the provider

    The Pulumi provider needs credentials to authenticate requests from your computer to Kurrent Cloud. Your credentials are never sent to pulumi.com. The provider needs to be configured with Kurrent Cloud credentials before it can be used to create resources.

    The provider supports two authentication methods:

    • Service Account credentials (recommended for automation) - configure clientId and clientSecret with the credentials of a Kurrent Cloud Service Account. The provider then obtains short-lived access tokens via the OAuth2 client-credentials grant, and token is not used.
    • Refresh token - configure token with a personal refresh token. This is the legacy method; the token is bound to a user account.

    In both cases you also need the organization id: go to the list of organizations you have access to in the Kurrent Cloud console, choose the organization that you will be provisioning resources for, and find the organization id in the settings.

    Service Account credentials can be provided via environment variables:

    $ export ESC_CLIENT_ID=<YOUR_CLIENT_ID>
    $ export ESC_CLIENT_SECRET=<YOUR_CLIENT_SECRET>
    $ export ESC_ORG_ID=<YOUR_ORGANIZATION_ID>
    

    or via stack configuration:

    pulumi config set kurrentcloud:clientId <YOUR_CLIENT_ID>
    pulumi config set kurrentcloud:clientSecret <YOUR_CLIENT_SECRET> --secret
    pulumi config set kurrentcloud:organizationId <YOUR_ORGANIZATION_ID> --secret
    

    Refresh token authentication works the same way. First, you need an access token for your user, which you can obtain from the Kurrent Cloud console.

    • <YOUR_ACCESS_TOKEN>: your access token
    • <YOUR_ORGANIZATION_ID>: the Kurrent Cloud organization id

    Once the credentials are obtained, there are two ways to communicate your authorization tokens to Pulumi:

    1. Set the environment variables ESC_TOKEN and ESC_ORG_ID:

      $ export ESC_TOKEN=<YOUR_ACCESS_TOKEN>
      $ export ESC_ORG_ID=<YOUR_ORGANIZATION_ID>
      
    2. Set them using configuration, if you prefer that they be stored alongside your Pulumi stack for easy multi-user access:

      pulumi config set kurrentcloud:token <YOUR_ACCESS_TOKEN> --secret
      pulumi config set kurrentcloud:organizationId <YOUR_ORGANIZATION_ID> --secret
      
    Required options can be omitted if you configure them using environment variables.
    OptionRequired/OptionalDescription
    tokenRequired unless Service Account credentials are setRefresh token. You can retrieve this from the ‘Access Tokens’ section of the Kurrent Cloud console.
    organizationIdRequiredThe organization id. You can find it in the organization settings page of the Kurrent Cloud console.
    clientIdOptionalService Account client id. Must be set together with clientSecret.
    clientSecretOptionalService Account client secret. When both clientId and clientSecret are set, Service Account authentication is used and takes priority over token.
    urlOptionalThe URL of the Kurrent Cloud API. This defaults to the public cloud instance of Kurrent Cloud.
    tokenStoreOptionalThe location on the local filesystem of the token cache. This is shared with the Kurrent CLI. Only used with refresh token authentication.
    identityKitUrlOptionalThe base URL of the token endpoint used for Service Account authentication. You would normally not need to set it.
    kurrentcloud logo Kurrent Cloud
    Viewing docs for Kurrent Cloud v0.3.1
    published on Tuesday, Oct 6, 2026 by Kurrent

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial