published on Friday, Sep 18, 2026 by Pulumi
published on Friday, Sep 18, 2026 by Pulumi
Manages an RFC2136 DNS provider configuration for PKI External CA DNS-01 ACME challenges.
RFC2136 allows Vault to perform dynamic DNS updates directly against an authoritative nameserver
(e.g. BIND with allow-update).
Important All data provided in the resource configuration will be written in cleartext to state and plan files generated by Terraform, and will appear in the console output when Terraform runs. Protect these artifacts accordingly. See the main provider documentation for more details.
This resource requires Vault 2.1.0 or later.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as vault from "@pulumi/vault";
const pki_external_ca = new vault.Mount("pki-external-ca", {
path: "pki-external-ca",
type: "pki-external-ca",
});
const example = new vault.pkiexternalca.SecretBackendDnsProviderRfc2136("example", {
mount: pki_external_ca.path,
name: "my-rfc2136-provider",
identifiers: [
"example.com",
"*.example.com",
],
nameserver: "192.168.1.1:53",
tsigKeyName: "vault-key.",
tsigSecretWo: tsigSecret,
tsigSecretWoVersion: 1,
tsigAlgorithm: "hmac-sha256",
});
import pulumi
import pulumi_vault as vault
pki_external_ca = vault.Mount("pki-external-ca",
path="pki-external-ca",
type="pki-external-ca")
example = vault.pkiexternalca.SecretBackendDnsProviderRfc2136("example",
mount=pki_external_ca.path,
name="my-rfc2136-provider",
identifiers=[
"example.com",
"*.example.com",
],
nameserver="192.168.1.1:53",
tsig_key_name="vault-key.",
tsig_secret_wo=tsig_secret,
tsig_secret_wo_version=1,
tsig_algorithm="hmac-sha256")
package main
import (
"github.com/pulumi/pulumi-vault/sdk/v7/go/vault"
"github.com/pulumi/pulumi-vault/sdk/v7/go/vault/pkiexternalca"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
pki_external_ca, err := vault.NewMount(ctx, "pki-external-ca", &vault.MountArgs{
Path: pulumi.String("pki-external-ca"),
Type: pulumi.String("pki-external-ca"),
})
if err != nil {
return err
}
_, err = pkiexternalca.NewSecretBackendDnsProviderRfc2136(ctx, "example", &pkiexternalca.SecretBackendDnsProviderRfc2136Args{
Mount: pki_external_ca.Path,
Name: pulumi.String("my-rfc2136-provider"),
Identifiers: pulumi.StringArray{
pulumi.String("example.com"),
pulumi.String("*.example.com"),
},
Nameserver: pulumi.String("192.168.1.1:53"),
TsigKeyName: pulumi.String("vault-key."),
TsigSecretWo: pulumi.Any(tsigSecret),
TsigSecretWoVersion: pulumi.Int(1),
TsigAlgorithm: pulumi.String("hmac-sha256"),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Vault = Pulumi.Vault;
return await Deployment.RunAsync(() =>
{
var pki_external_ca = new Vault.Mount("pki-external-ca", new()
{
Path = "pki-external-ca",
Type = "pki-external-ca",
});
var example = new Vault.PkiExternalCa.SecretBackendDnsProviderRfc2136("example", new()
{
Mount = pki_external_ca.Path,
Name = "my-rfc2136-provider",
Identifiers = new[]
{
"example.com",
"*.example.com",
},
Nameserver = "192.168.1.1:53",
TsigKeyName = "vault-key.",
TsigSecretWo = tsigSecret,
TsigSecretWoVersion = 1,
TsigAlgorithm = "hmac-sha256",
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.vault.Mount;
import com.pulumi.vault.MountArgs;
import com.pulumi.vault.pkiexternalca.SecretBackendDnsProviderRfc2136;
import com.pulumi.vault.pkiexternalca.SecretBackendDnsProviderRfc2136Args;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var pki_external_ca = new Mount("pki-external-ca", MountArgs.builder()
.path("pki-external-ca")
.type("pki-external-ca")
.build());
var example = new SecretBackendDnsProviderRfc2136("example", SecretBackendDnsProviderRfc2136Args.builder()
.mount(pki_external_ca.path())
.name("my-rfc2136-provider")
.identifiers(
"example.com",
"*.example.com")
.nameserver("192.168.1.1:53")
.tsigKeyName("vault-key.")
.tsigSecretWo(tsigSecret)
.tsigSecretWoVersion(1)
.tsigAlgorithm("hmac-sha256")
.build());
}
}
resources:
pki-external-ca:
type: vault:Mount
properties:
path: pki-external-ca
type: pki-external-ca
example:
type: vault:pkiexternalca:SecretBackendDnsProviderRfc2136
properties:
mount: ${["pki-external-ca"].path}
name: my-rfc2136-provider
identifiers:
- example.com
- '*.example.com'
nameserver: 192.168.1.1:53
tsigKeyName: vault-key.
tsigSecretWo: ${tsigSecret}
tsigSecretWoVersion: 1
tsigAlgorithm: hmac-sha256
pulumi {
required_providers {
vault = {
source = "pulumi/vault"
}
}
}
resource "vault_mount" "pki-external-ca" {
path = "pki-external-ca"
type = "pki-external-ca"
}
resource "vault_pkiexternalca_secretbackenddnsproviderrfc2136" "example" {
mount = vault_mount.pki-external-ca.path
name = "my-rfc2136-provider"
identifiers = ["example.com", "*.example.com"]
nameserver = "192.168.1.1:53"
tsig_key_name = "vault-key."
tsig_secret_wo = tsigSecret
tsig_secret_wo_version = 1
tsig_algorithm = "hmac-sha256"
}
Create SecretBackendDnsProviderRfc2136 Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new SecretBackendDnsProviderRfc2136(name: string, args: SecretBackendDnsProviderRfc2136Args, opts?: CustomResourceOptions);@overload
def SecretBackendDnsProviderRfc2136(resource_name: str,
args: SecretBackendDnsProviderRfc2136Args,
opts: Optional[ResourceOptions] = None)
@overload
def SecretBackendDnsProviderRfc2136(resource_name: str,
opts: Optional[ResourceOptions] = None,
identifiers: Optional[Sequence[str]] = None,
mount: Optional[str] = None,
nameserver: Optional[str] = None,
tsig_key_name: Optional[str] = None,
tsig_secret_wo: Optional[str] = None,
tsig_secret_wo_version: Optional[int] = None,
name: Optional[str] = None,
namespace: Optional[str] = None,
tsig_algorithm: Optional[str] = None,
ttl: Optional[int] = None)func NewSecretBackendDnsProviderRfc2136(ctx *Context, name string, args SecretBackendDnsProviderRfc2136Args, opts ...ResourceOption) (*SecretBackendDnsProviderRfc2136, error)public SecretBackendDnsProviderRfc2136(string name, SecretBackendDnsProviderRfc2136Args args, CustomResourceOptions? opts = null)
public SecretBackendDnsProviderRfc2136(String name, SecretBackendDnsProviderRfc2136Args args)
public SecretBackendDnsProviderRfc2136(String name, SecretBackendDnsProviderRfc2136Args args, CustomResourceOptions options)
type: vault:pkiexternalca:SecretBackendDnsProviderRfc2136
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "vault_pkiexternalca_secret_backend_dns_provider_rfc2136" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args SecretBackendDnsProviderRfc2136Args
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args SecretBackendDnsProviderRfc2136Args
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args SecretBackendDnsProviderRfc2136Args
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args SecretBackendDnsProviderRfc2136Args
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args SecretBackendDnsProviderRfc2136Args
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var secretBackendDnsProviderRfc2136Resource = new Vault.PkiExternalCa.SecretBackendDnsProviderRfc2136("secretBackendDnsProviderRfc2136Resource", new()
{
Identifiers = new[]
{
"string",
},
Mount = "string",
Nameserver = "string",
TsigKeyName = "string",
TsigSecretWo = "string",
TsigSecretWoVersion = 0,
Name = "string",
Namespace = "string",
TsigAlgorithm = "string",
Ttl = 0,
});
example, err := pkiexternalca.NewSecretBackendDnsProviderRfc2136(ctx, "secretBackendDnsProviderRfc2136Resource", &pkiexternalca.SecretBackendDnsProviderRfc2136Args{
Identifiers: pulumi.StringArray{
pulumi.String("string"),
},
Mount: pulumi.String("string"),
Nameserver: pulumi.String("string"),
TsigKeyName: pulumi.String("string"),
TsigSecretWo: pulumi.String("string"),
TsigSecretWoVersion: pulumi.Int(0),
Name: pulumi.String("string"),
Namespace: pulumi.String("string"),
TsigAlgorithm: pulumi.String("string"),
Ttl: pulumi.Int(0),
})
resource "vault_pkiexternalca_secret_backend_dns_provider_rfc2136" "secretBackendDnsProviderRfc2136Resource" {
lifecycle {
create_before_destroy = true
}
identifiers = ["string"]
mount = "string"
nameserver = "string"
tsig_key_name = "string"
tsig_secret_wo = "string"
tsig_secret_wo_version = 0
name = "string"
namespace = "string"
tsig_algorithm = "string"
ttl = 0
}
var secretBackendDnsProviderRfc2136Resource = new SecretBackendDnsProviderRfc2136("secretBackendDnsProviderRfc2136Resource", SecretBackendDnsProviderRfc2136Args.builder()
.identifiers("string")
.mount("string")
.nameserver("string")
.tsigKeyName("string")
.tsigSecretWo("string")
.tsigSecretWoVersion(0)
.name("string")
.namespace("string")
.tsigAlgorithm("string")
.ttl(0)
.build());
secret_backend_dns_provider_rfc2136_resource = vault.pkiexternalca.SecretBackendDnsProviderRfc2136("secretBackendDnsProviderRfc2136Resource",
identifiers=["string"],
mount="string",
nameserver="string",
tsig_key_name="string",
tsig_secret_wo="string",
tsig_secret_wo_version=0,
name="string",
namespace="string",
tsig_algorithm="string",
ttl=0)
const secretBackendDnsProviderRfc2136Resource = new vault.pkiexternalca.SecretBackendDnsProviderRfc2136("secretBackendDnsProviderRfc2136Resource", {
identifiers: ["string"],
mount: "string",
nameserver: "string",
tsigKeyName: "string",
tsigSecretWo: "string",
tsigSecretWoVersion: 0,
name: "string",
namespace: "string",
tsigAlgorithm: "string",
ttl: 0,
});
type: vault:pkiexternalca:SecretBackendDnsProviderRfc2136
properties:
identifiers:
- string
mount: string
name: string
nameserver: string
namespace: string
tsigAlgorithm: string
tsigKeyName: string
tsigSecretWo: string
tsigSecretWoVersion: 0
ttl: 0
SecretBackendDnsProviderRfc2136 Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The SecretBackendDnsProviderRfc2136 resource accepts the following input properties:
- Identifiers List<string>
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - Mount string
- The path where the PKI External CA secret backend is mounted.
- Nameserver string
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - Tsig
Key stringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - Tsig
Secret stringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- Tsig
Secret intWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - Name string
- Name of the DNS provider configuration. Must be unique within the backend.
- Namespace string
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - Tsig
Algorithm string - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - Ttl int
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- Identifiers []string
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - Mount string
- The path where the PKI External CA secret backend is mounted.
- Nameserver string
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - Tsig
Key stringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - Tsig
Secret stringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- Tsig
Secret intWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - Name string
- Name of the DNS provider configuration. Must be unique within the backend.
- Namespace string
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - Tsig
Algorithm string - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - Ttl int
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- identifiers list(string)
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - mount string
- The path where the PKI External CA secret backend is mounted.
- nameserver string
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - tsig_
key_ stringname - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig_
secret_ stringwo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig_
secret_ numberwo_ version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - name string
- Name of the DNS provider configuration. Must be unique within the backend.
- namespace string
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig_
algorithm string - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - ttl number
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- identifiers List<String>
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - mount String
- The path where the PKI External CA secret backend is mounted.
- nameserver String
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - tsig
Key StringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig
Secret StringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig
Secret IntegerWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - name String
- Name of the DNS provider configuration. Must be unique within the backend.
- namespace String
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig
Algorithm String - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - ttl Integer
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- identifiers string[]
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - mount string
- The path where the PKI External CA secret backend is mounted.
- nameserver string
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - tsig
Key stringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig
Secret stringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig
Secret numberWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - name string
- Name of the DNS provider configuration. Must be unique within the backend.
- namespace string
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig
Algorithm string - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - ttl number
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- identifiers Sequence[str]
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - mount str
- The path where the PKI External CA secret backend is mounted.
- nameserver str
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - tsig_
key_ strname - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig_
secret_ strwo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig_
secret_ intwo_ version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - name str
- Name of the DNS provider configuration. Must be unique within the backend.
- namespace str
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig_
algorithm str - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - ttl int
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- identifiers List<String>
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - mount String
- The path where the PKI External CA secret backend is mounted.
- nameserver String
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - tsig
Key StringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig
Secret StringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig
Secret NumberWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - name String
- Name of the DNS provider configuration. Must be unique within the backend.
- namespace String
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig
Algorithm String - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - ttl Number
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
Outputs
All input properties are implicitly available as output properties. Additionally, the SecretBackendDnsProviderRfc2136 resource produces the following output properties:
- Creation
Date string - The date and time the provider was created.
- Id string
- The provider-assigned unique ID for this managed resource.
- Last
Updated stringDate - The date and time the provider was last updated.
- Creation
Date string - The date and time the provider was created.
- Id string
- The provider-assigned unique ID for this managed resource.
- Last
Updated stringDate - The date and time the provider was last updated.
- creation_
date string - The date and time the provider was created.
- id string
- The provider-assigned unique ID for this managed resource.
- last_
updated_ stringdate - The date and time the provider was last updated.
- creation
Date String - The date and time the provider was created.
- id String
- The provider-assigned unique ID for this managed resource.
- last
Updated StringDate - The date and time the provider was last updated.
- creation
Date string - The date and time the provider was created.
- id string
- The provider-assigned unique ID for this managed resource.
- last
Updated stringDate - The date and time the provider was last updated.
- creation_
date str - The date and time the provider was created.
- id str
- The provider-assigned unique ID for this managed resource.
- last_
updated_ strdate - The date and time the provider was last updated.
- creation
Date String - The date and time the provider was created.
- id String
- The provider-assigned unique ID for this managed resource.
- last
Updated StringDate - The date and time the provider was last updated.
Look up Existing SecretBackendDnsProviderRfc2136 Resource
Get an existing SecretBackendDnsProviderRfc2136 resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: SecretBackendDnsProviderRfc2136State, opts?: CustomResourceOptions): SecretBackendDnsProviderRfc2136@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
creation_date: Optional[str] = None,
identifiers: Optional[Sequence[str]] = None,
last_updated_date: Optional[str] = None,
mount: Optional[str] = None,
name: Optional[str] = None,
nameserver: Optional[str] = None,
namespace: Optional[str] = None,
tsig_algorithm: Optional[str] = None,
tsig_key_name: Optional[str] = None,
tsig_secret_wo: Optional[str] = None,
tsig_secret_wo_version: Optional[int] = None,
ttl: Optional[int] = None) -> SecretBackendDnsProviderRfc2136func GetSecretBackendDnsProviderRfc2136(ctx *Context, name string, id IDInput, state *SecretBackendDnsProviderRfc2136State, opts ...ResourceOption) (*SecretBackendDnsProviderRfc2136, error)public static SecretBackendDnsProviderRfc2136 Get(string name, Input<string> id, SecretBackendDnsProviderRfc2136State? state, CustomResourceOptions? opts = null)public static SecretBackendDnsProviderRfc2136 get(String name, Output<String> id, SecretBackendDnsProviderRfc2136State state, CustomResourceOptions options)resources: _: type: vault:pkiexternalca:SecretBackendDnsProviderRfc2136 get: id: ${id}import {
to = vault_pkiexternalca_secret_backend_dns_provider_rfc2136.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Creation
Date string - The date and time the provider was created.
- Identifiers List<string>
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - Last
Updated stringDate - The date and time the provider was last updated.
- Mount string
- The path where the PKI External CA secret backend is mounted.
- Name string
- Name of the DNS provider configuration. Must be unique within the backend.
- Nameserver string
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - Namespace string
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - Tsig
Algorithm string - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - Tsig
Key stringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - Tsig
Secret stringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- Tsig
Secret intWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - Ttl int
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- Creation
Date string - The date and time the provider was created.
- Identifiers []string
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - Last
Updated stringDate - The date and time the provider was last updated.
- Mount string
- The path where the PKI External CA secret backend is mounted.
- Name string
- Name of the DNS provider configuration. Must be unique within the backend.
- Nameserver string
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - Namespace string
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - Tsig
Algorithm string - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - Tsig
Key stringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - Tsig
Secret stringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- Tsig
Secret intWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - Ttl int
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- creation_
date string - The date and time the provider was created.
- identifiers list(string)
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - last_
updated_ stringdate - The date and time the provider was last updated.
- mount string
- The path where the PKI External CA secret backend is mounted.
- name string
- Name of the DNS provider configuration. Must be unique within the backend.
- nameserver string
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - namespace string
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig_
algorithm string - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - tsig_
key_ stringname - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig_
secret_ stringwo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig_
secret_ numberwo_ version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - ttl number
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- creation
Date String - The date and time the provider was created.
- identifiers List<String>
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - last
Updated StringDate - The date and time the provider was last updated.
- mount String
- The path where the PKI External CA secret backend is mounted.
- name String
- Name of the DNS provider configuration. Must be unique within the backend.
- nameserver String
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - namespace String
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig
Algorithm String - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - tsig
Key StringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig
Secret StringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig
Secret IntegerWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - ttl Integer
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- creation
Date string - The date and time the provider was created.
- identifiers string[]
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - last
Updated stringDate - The date and time the provider was last updated.
- mount string
- The path where the PKI External CA secret backend is mounted.
- name string
- Name of the DNS provider configuration. Must be unique within the backend.
- nameserver string
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - namespace string
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig
Algorithm string - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - tsig
Key stringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig
Secret stringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig
Secret numberWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - ttl number
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- creation_
date str - The date and time the provider was created.
- identifiers Sequence[str]
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - last_
updated_ strdate - The date and time the provider was last updated.
- mount str
- The path where the PKI External CA secret backend is mounted.
- name str
- Name of the DNS provider configuration. Must be unique within the backend.
- nameserver str
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - namespace str
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig_
algorithm str - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - tsig_
key_ strname - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig_
secret_ strwo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig_
secret_ intwo_ version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - ttl int
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
- creation
Date String - The date and time the provider was created.
- identifiers List<String>
- List of domain identifiers this provider handles. Supports wildcard patterns with a leftmost
*(e.g.*.example.com). - last
Updated StringDate - The date and time the provider was last updated.
- mount String
- The path where the PKI External CA secret backend is mounted.
- name String
- Name of the DNS provider configuration. Must be unique within the backend.
- nameserver String
- Address of the authoritative nameserver to send RFC2136 dynamic update requests to, in
IP:portformat (e.g.192.168.1.1:53). Also used as the verification nameserver for this provider. - namespace String
- The namespace to provision the resource in.
The value should not contain leading or trailing forward slashes.
The
namespaceis always relative to the provider's configured namespace. Available only for Vault Enterprise. - tsig
Algorithm String - TSIG algorithm to use. Valid values are
hmac-sha1,hmac-sha224,hmac-sha256,hmac-sha384,hmac-sha512. Defaults tohmac-sha256. - tsig
Key StringName - TSIG key name for authenticated DNS updates (e.g.
vault-key.). - tsig
Secret StringWo - NOTE: This field is write-only and its value will not be updated in state as part of read operations. TSIG secret as a base64-encoded string. Write-only — never stored in Terraform state.
- tsig
Secret NumberWo Version - Version counter for
tsigSecretWo. Increment this to trigger an update to the TSIG secret in Vault without changing any other field. - ttl Number
- TTL for DNS TXT records used in DNS-01 challenges. Defaults to
60s.
Import
RFC2136 DNS provider configurations can be imported using the format <mount>/config/dns/rfc2136/<name>, e.g.
$ pulumi import vault:pkiexternalca/secretBackendDnsProviderRfc2136:SecretBackendDnsProviderRfc2136 example pki-external-ca/config/dns/rfc2136/my-rfc2136-provider
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- Vault pulumi/pulumi-vault
- License
- Apache-2.0
- Notes
- This Pulumi package is based on the
vaultTerraform Provider.
published on Friday, Sep 18, 2026 by Pulumi