// *** WARNING: this file was generated by pulumi-language-nodejs. *** // *** Do not edit by hand unless you're certain you know what you are doing! *** import * as pulumi from "@pulumi/pulumi"; import * as utilities from "./utilities"; /** * An external secret manager Dokploy resolves environment variables from at deploy time. * * Reference a secret from any `env` value with `${{vault..}}`. The value is fetched when the deployment runs and is never stored in Dokploy — so rotating it in the vault takes effect on the next deploy with no Terraform change. * * Supported `providerType` values: `hashicorp` (Vault/OpenBao), `infisical`, `aws` (Secrets Manager), `doppler`, `azure` (Key Vault) and `scaleway`. */ export class VaultProvider extends pulumi.CustomResource { /** * Get an existing VaultProvider resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ public static get(name: string, id: pulumi.Input, state?: VaultProviderState, opts?: pulumi.CustomResourceOptions): VaultProvider { return new VaultProvider(name, state, { ...opts, id: id }); } /** @internal */ public static readonly __pulumiType = 'dokploy:index/vaultProvider:VaultProvider'; /** * Returns true if the given object is an instance of VaultProvider. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ public static isInstance(obj: any): obj is VaultProvider { if (obj === undefined || obj === null) { return false; } return obj['__pulumiType'] === VaultProvider.__pulumiType; } /** * JSON array scoping which projects or environments may resolve secrets from this provider. Pass `jsonencode([])` to leave it unscoped. */ declare public readonly assignments: pulumi.Output; /** * Provider credentials as a JSON object, including the `providerType` discriminator. */ declare public readonly config: pulumi.Output; /** * RFC 3339 timestamp of when the connection was created. */ declare public /*out*/ readonly createdAt: pulumi.Output; /** * Name of the connection, unique within the organization. */ declare public readonly name: pulumi.Output; /** * Organization that owns the connection. */ declare public /*out*/ readonly organizationId: pulumi.Output; /** * Provider kind derived from `config`. */ declare public /*out*/ readonly providerType: pulumi.Output; /** * Create a VaultProvider resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: VaultProviderArgs, opts?: pulumi.CustomResourceOptions) constructor(name: string, argsOrState?: VaultProviderArgs | VaultProviderState, opts?: pulumi.CustomResourceOptions) { let resourceInputs: pulumi.Inputs = {}; opts = opts || {}; if (opts.id) { const state = argsOrState as VaultProviderState | undefined; resourceInputs["assignments"] = state?.assignments; resourceInputs["config"] = state?.config; resourceInputs["createdAt"] = state?.createdAt; resourceInputs["name"] = state?.name; resourceInputs["organizationId"] = state?.organizationId; resourceInputs["providerType"] = state?.providerType; } else { const args = argsOrState as VaultProviderArgs | undefined; if (args?.assignments === undefined && !opts.urn) { throw new Error("Missing required property 'assignments'"); } if (args?.config === undefined && !opts.urn) { throw new Error("Missing required property 'config'"); } resourceInputs["assignments"] = args?.assignments; resourceInputs["config"] = args?.config ? pulumi.secret(args.config) : undefined; resourceInputs["name"] = args?.name; resourceInputs["createdAt"] = undefined /*out*/; resourceInputs["organizationId"] = undefined /*out*/; resourceInputs["providerType"] = undefined /*out*/; } opts = pulumi.mergeOptions(utilities.resourceOptsDefaults(), opts); const secretOpts = { additionalSecretOutputs: ["config"] }; opts = pulumi.mergeOptions(opts, secretOpts); super(VaultProvider.__pulumiType, name, resourceInputs, opts); } } /** * Input properties used for looking up and filtering VaultProvider resources. */ export interface VaultProviderState { /** * JSON array scoping which projects or environments may resolve secrets from this provider. Pass `jsonencode([])` to leave it unscoped. */ assignments?: pulumi.Input; /** * Provider credentials as a JSON object, including the `providerType` discriminator. */ config?: pulumi.Input; /** * RFC 3339 timestamp of when the connection was created. */ createdAt?: pulumi.Input; /** * Name of the connection, unique within the organization. */ name?: pulumi.Input; /** * Organization that owns the connection. */ organizationId?: pulumi.Input; /** * Provider kind derived from `config`. */ providerType?: pulumi.Input; } /** * The set of arguments for constructing a VaultProvider resource. */ export interface VaultProviderArgs { /** * JSON array scoping which projects or environments may resolve secrets from this provider. Pass `jsonencode([])` to leave it unscoped. */ assignments: pulumi.Input; /** * Provider credentials as a JSON object, including the `providerType` discriminator. */ config: pulumi.Input; /** * Name of the connection, unique within the organization. */ name?: pulumi.Input; }