| acme_challenge |
String |
ACME challenge type. Options: [dns] |
[optional][default to 'dns'] |
| delete_protection |
String |
Protection from accidental deletion of this object [true/false] |
[optional] |
| description |
String |
Description of the object |
[optional] |
| digicert_url |
String |
DigiCert ACME endpoint selector. Options: [us-production/eu-production/us-demo/eu-demo] |
[optional][default to 'us-production'] |
| dns_propagation_wait |
String |
Fixed wait after TXT publish (e.g. 30s, 2m). If omitted with pre-check on, no extra sleep (polling only). If omitted with --dns-skip-precheck, gateway uses 30s. DNS challenge only |
[optional] |
| dns_resolvers |
Array<String> |
Custom DNS resolvers (ip:port) for DNS-01. Repeat for multiple. If omitted, Lego uses /etc/resolv.conf or Google Public DNS. DNS challenge only |
[optional] |
| dns_skip_precheck |
Boolean |
Skip DNS TXT pre-check before CA validation. If --dns-propagation-wait is omitted and this flag is set, gateway waits 30s before CA validation. DNS challenge only |
[optional] |
| dns_target_creds |
String |
Name of existing cloud target for DNS credentials. Required when challenge type is dns. Supported providers: AWS, Azure, GCP, Cloudflare |
[optional] |
| dns_timeout |
String |
Per-query DNS lookup timeout during pre-check (e.g. 10s), not total poll time. If omitted with pre-check on, Lego library default applies (10s per query on Linux). Ignored when --dns-skip-precheck is set. DNS challenge only |
[optional] |
| dns_zone |
String |
Cloudflare DNS zone identifier. Required when DNS credentials target is Cloudflare |
[optional] |
| eab_hmac_key |
String |
External Account Binding HMAC key (required for ACME account bootstrap on create) |
[optional] |
| eab_key_id |
String |
External Account Binding key identifier (required for ACME account bootstrap on create) |
[optional] |
| email |
String |
Email address for ACME account registration |
|
| gcp_project |
String |
GCP Cloud DNS project ID. Optional and can be derived from service account |
[optional] |
| hosted_zone |
String |
AWS Route53 hosted zone ID. Required when DNS credentials target is AWS |
[optional] |
| json |
Boolean |
Set output format to JSON |
[optional][default to false] |
| key |
String |
The name of a key that used to encrypt the target secret value (if empty, the account default protectionKey key will be used) |
[optional] |
| lock_on_read |
String |
Lock this secret after each successful value read |
[optional] |
| lock_ttl |
String |
Lock TTL in minutes |
[optional] |
| max_versions |
String |
Set the maximum number of versions, limited by the account settings defaults. |
[optional] |
| name |
String |
Target name |
|
| resource_group |
String |
Azure resource group name. Required when DNS credentials target is Azure |
[optional] |
| rotate_on_unlock |
String |
Rotate this secret after it is unlocked |
[optional] |
| timeout |
String |
Timeout for challenge validation |
[optional][default to '5m'] |
| token |
String |
Authentication token (see `/auth` and `/configure`) |
[optional] |
| uid_token |
String |
The universal identity token, Required only for universal_identity authentication |
[optional] |