DbaaS Postgres
Database Client Certificate
Terraform reference for Database Client Certificate.
Schema Properties
| Property | Type | Description |
|---|---|---|
ca_chain Computed | string | The CA chain content in PEM format, if applicable. Examples: -----BEGIN CERTIFICATE-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ...
-----END CERTIFICATE----- |
certificate Computed | string | The client certificate content in PEM format. Examples: -----BEGIN CERTIFICATE-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ...
-----END CERTIFICATE----- |
certificate_location Computed | string | The location within the Vault secret where the client certificate can be found. |
csr RequiredForceNew | string | The Certificate Signing Request (CSR) content in PEM format used to generate the client certificate. It must be a RSA key of minimum 4096 bits. Examples: -----BEGIN CERTIFICATE REQUEST-----
MIIBVzCBuAIBADA7MQswCQYDVQQGEwJVUzELMAkGA1UECBMCQ0ExETAPBgNVBAcTCFNhbiBSYW1vbjEPMA0GA1UEChMGRXhhbXBsZTENMAsGA1UECxMEVGVzdDEWMBQGA1UEAxMNY2xpZW50LmV4YW1wbGUuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQ...
-----END CERTIFICATE REQUEST----- |
database_id Required | string | Asset ID of the parent database (platform/region/architecture/dbName). Used by the platform to register a parent relation and validate the database exists at creation time. Examples: sb/eu/2/axis_mydbsb/eu/2/core_mydb |
expiration_time Computed | string | The expiration time of the client certificate. Examples: 2024-12-31T23:59:59Z |
role_id Required | string | Asset ID of the parent database role. Used by the platform to register a parent relation and validate the role exists at creation time. Examples: sb/eu/axis_mydb/axis_mydb_writersb/eu/core_mydb/core_mydb_reader |
serial_number Computed | string | The serial number of the client certificate as reported by Vault PKI (colon-separated hex, e.g. "1a:2b:3c:…"). Used to revoke the certificate. Examples: 1a:2b:3c:4d:5e:6f |
ttl RequiredForceNew | string | Time to live for the client certificate. Accepts year shorthand (e.g. "1y"), day shorthand (e.g. "90d"), or Go duration format (e.g. "26280h"). Min: 1 month (720h). Max: 3 years. Examples: 3y90d26280h |
resource "gi_dbaas_pg_database_client_certificate" "example" { attributes = { csr = "example-csr" database_id = "example-database_id" role_id = "example-role_id" ttl = "example-ttl" }}