PATCH
/
api
/
v1
/
auth
/
kubernetes-auth
/
identities
/
{identityId}

Authorizations

Authorization
string
headerrequired

An access token in Infisical

Path Parameters

identityId
string
required

The ID of the identity to update the auth method for.

Body

application/json
kubernetesHost
string

The new host string, host:port pair, or URL to the base of the Kubernetes API server.

caCert
string

The new PEM-encoded CA cert for the Kubernetes API server.

tokenReviewerJwt
string

The new long-lived service account JWT token for Infisical to access the TokenReview API to validate other service account JWT tokens submitted by applications/pods.

allowedNamespaces
string

The new comma-separated list of trusted namespaces that service accounts must belong to authenticate with Infisical.

allowedNames
string

The new comma-separated list of trusted service account names that can authenticate with Infisical.

allowedAudience
string

The new optional audience claim that the service account JWT token must have to authenticate with Infisical.

accessTokenTrustedIps
object[]

The new IPs or CIDR ranges that access tokens can be used from.

accessTokenTTL
integer

The new lifetime for an acccess token in seconds.

accessTokenNumUsesLimit
integer

The new maximum number of times that an access token can be used.

accessTokenMaxTTL
integer

The new maximum lifetime for an acccess token in seconds.

Response

200 - application/json
identityKubernetesAuth
object
required

Was this page helpful?