Skip to content

Latest commit

 

History

History
35 lines (27 loc) · 3.39 KB

AuthMethodCreateGcp.md

File metadata and controls

35 lines (27 loc) · 3.39 KB

AuthMethodCreateGcp

authMethodCreateGcp is a command that creates a new auth method that will be able to authenticate using GCP IAM Service Account credentials or GCE instance credentials.

Properties

Name Type Description Notes
accessExpires Long Access expiration date in Unix timestamp (select 0 for access without expiry date) [optional]
audience String The audience to verify in the JWT received by the client
auditLogsClaims List<String> Subclaims to include in audit logs, e.g &quot;--audit-logs-claims email --audit-logs-claims username&quot; [optional]
boundIps List<String> A CIDR whitelist with the IPs that the access is restricted to [optional]
boundLabels List<String> A comma-separated list of GCP labels formatted as &quot;key:value&quot; strings that must be set on authorized GCE instances. TODO: Because GCP labels are not currently ACL'd .... [optional]
boundProjects List<String> === Human and Machine authentication section === Array of GCP project IDs. Only entities belonging to any of the provided projects can authenticate. [optional]
boundRegions List<String> List of regions that a GCE instance must belong to in order to be authenticated. TODO: If bound_instance_groups is provided, it is assumed to be a regional group and the group must belong to this region. If bound_zones are provided, this attribute is ignored. [optional]
boundServiceAccounts List<String> List of service accounts the service account must be part of in order to be authenticated. [optional]
boundZones List<String> === Machine authentication section === List of zones that a GCE instance must belong to in order to be authenticated. TODO: If bound_instance_groups is provided, it is assumed to be a zonal group and the group must belong to this zone. [optional]
deleteProtection String Protection from accidental deletion of this object [true/false] [optional]
description String Auth Method description [optional]
forceSubClaims Boolean if true: enforce role-association must include sub claims [optional]
gwBoundIps List<String> A CIDR whitelist with the GW IPs that the access is restricted to [optional]
json Boolean Set output format to JSON [optional]
jwtTtl Long Jwt TTL [optional]
name String Auth Method name
productType List<String> Choose the relevant product type for the auth method [sm, sra, pm, dp, ca] [optional]
serviceAccountCredsData String ServiceAccount credentials data instead of giving a file path, base64 encoded [optional]
token String Authentication token (see `/auth` and `/configure`) [optional]
type String Type of the GCP Access Rules
uidToken String The universal identity token, Required only for universal_identity authentication [optional]
uniqueIdentifier String A unique identifier (ID) value which is a &quot;sub claim&quot; name that contains details uniquely identifying that resource. This &quot;sub claim&quot; is used to distinguish between different identities. [optional]