You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Protection from accidental deletion of this object [true/false]
[optional]
description
String
Description of the object
[optional]
dns_propagation_wait
String
Fixed wait after TXT publish (e.g. 30s, 2m). If omitted with pre-check on, no extra sleep (polling only). If omitted with --dns-skip-precheck, gateway uses 30s. DNS challenge only
[optional]
dns_resolvers
Array<String>
Custom DNS resolvers (ip:port) for DNS-01. Repeat for multiple. If omitted, Lego uses /etc/resolv.conf or Google Public DNS. DNS challenge only
[optional]
dns_skip_precheck
Boolean
Skip DNS TXT pre-check before CA validation. If --dns-propagation-wait is omitted and this flag is set, gateway waits 30s before CA validation. DNS challenge only
[optional]
dns_target_creds
String
Name of existing cloud target for DNS credentials. Required when acme-challenge=dns. Supported: AWS, Azure, GCP, Cloudflare targets
[optional]
dns_timeout
String
Per-query DNS lookup timeout during pre-check (e.g. 10s), not total poll time. If omitted with pre-check on, Lego library default applies (10s per query on Linux). Ignored when --dns-skip-precheck is set. DNS challenge only
[optional]
dns_zone
String
Cloudflare DNS zone identifier. Required when dns-target-creds points to Cloudflare target
[optional]
email
String
Email address for ACME account registration
gcp_project
String
GCP Cloud DNS: Project ID. Optional - can be derived from service account
[optional]
hosted_zone
String
AWS Route53 hosted zone ID. Required when dns-target-creds points to AWS target
[optional]
json
Boolean
Set output format to JSON
[optional][default to false]
keep_prev_version
String
Whether to keep previous version [true/false]. If not set, use default according to account settings
[optional]
key
String
The name of a key that used to encrypt the target secret value (if empty, the account default protectionKey key will be used)
[optional]
lets_encrypt_url
String
[optional][default to 'production']
lock_on_read
String
Lock this secret after each successful value read
[optional]
lock_ttl
String
Lock TTL in minutes
[optional]
max_versions
String
Set the maximum number of versions, limited by the account settings defaults.
[optional]
name
String
Target name
new_name
String
New target name
[optional]
resource_group
String
Azure resource group name. Required when dns-target-creds points to Azure target
[optional]
rotate_on_unlock
String
Rotate this secret after it is unlocked
[optional]
timeout
String
[optional][default to '5m']
token
String
Authentication token (see `/auth` and `/configure`)
[optional]
uid_token
String
The universal identity token, Required only for universal_identity authentication