FederatedIdentityCredential

class FederatedIdentityCredential : KotlinCustomResource

Describes a federated identity credential. API Version: 2022-01-31-preview.

Example Usage

FederatedIdentityCredentialCreate

using System.Collections.Generic;
using System.Linq;
using Pulumi;
using AzureNative = Pulumi.AzureNative;
return await Deployment.RunAsync(() =>
{
var federatedIdentityCredential = new AzureNative.ManagedIdentity.FederatedIdentityCredential("federatedIdentityCredential", new()
{
Audiences = new[]
{
"api://AzureADTokenExchange",
},
FederatedIdentityCredentialResourceName = "ficResourceName",
Issuer = "https://oidc.prod-aks.azure.com/IssuerGUID",
ResourceGroupName = "rgName",
ResourceName = "resourceName",
Subject = "system:serviceaccount:ns:svcaccount",
});
});
package main
import (
managedidentity "github.com/pulumi/pulumi-azure-native-sdk/managedidentity"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := managedidentity.NewFederatedIdentityCredential(ctx, "federatedIdentityCredential", &managedidentity.FederatedIdentityCredentialArgs{
Audiences: pulumi.StringArray{
pulumi.String("api://AzureADTokenExchange"),
},
FederatedIdentityCredentialResourceName: pulumi.String("ficResourceName"),
Issuer: pulumi.String("https://oidc.prod-aks.azure.com/IssuerGUID"),
ResourceGroupName: pulumi.String("rgName"),
ResourceName: pulumi.String("resourceName"),
Subject: pulumi.String("system:serviceaccount:ns:svcaccount"),
})
if err != nil {
return err
}
return nil
})
}
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.azurenative.managedidentity.FederatedIdentityCredential;
import com.pulumi.azurenative.managedidentity.FederatedIdentityCredentialArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var federatedIdentityCredential = new FederatedIdentityCredential("federatedIdentityCredential", FederatedIdentityCredentialArgs.builder()
.audiences("api://AzureADTokenExchange")
.federatedIdentityCredentialResourceName("ficResourceName")
.issuer("https://oidc.prod-aks.azure.com/IssuerGUID")
.resourceGroupName("rgName")
.resourceName("resourceName")
.subject("system:serviceaccount:ns:svcaccount")
.build());
}
}

Import

An existing resource can be imported using its type token, name, and identifier, e.g.

$ pulumi import azure-native:managedidentity:FederatedIdentityCredential ficResourceName /subscriptions/subid/resourcegroups/rgName/providers/Microsoft.ManagedIdentity/userAssignedIdentities/identityName/federatedIdentityCredentials/ficResourceName

Properties

Link copied to clipboard
val audiences: Output<List<String>>

The list of audiences that can appear in the issued token.

Link copied to clipboard
val id: Output<String>
Link copied to clipboard
val issuer: Output<String>

The URL of the issuer to be trusted.

Link copied to clipboard
val name: Output<String>

The name of the resource

Link copied to clipboard
val pulumiChildResources: Set<KotlinResource>
Link copied to clipboard
Link copied to clipboard
Link copied to clipboard
val subject: Output<String>

The identifier of the external identity.

Link copied to clipboard
val type: Output<String>

The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts"

Link copied to clipboard
val urn: Output<String>