
Kestra Plugin Set
CertifiedCreate or update a role
Kestra Plugin Set
Create or update a role
Upserts a role by name: searches for an existing role with the given name and updates it if found, or creates a new one otherwise.
type: io.kestra.plugin.kestra.ee.iam.roles.SetExamples
Upsert a role.
id: iam_role_set
namespace: company.team
tasks:
- id: upsert_role
type: io.kestra.plugin.kestra.ee.iam.roles.Set
name: "data-engineer-role"
roleDescription: "Role for data engineers"
permissions:
FLOW:
- READ
- CREATE
EXECUTION:
- READ
Properties
name *Requiredstring
Role name
permissions *Requiredobject
Role permissions
Map of resource type to list of allowed actions, e.g. {"FLOW": ["READ", "CREATE"], "EXECUTION": ["READ"]}.
Valid resource types include: FLOW, BLUEPRINT, NAMESPACE, EXECUTION, USER, GROUP, ROLE, BINDING, AUDITLOG, SECRET, KVSTORE, SETTING, APP, ASSET, TEST, DASHBOARD, SERVICEACCOUNT, and others.
auth Non-dynamic
Select API authentication
Use either an API token or HTTP Basic (username/password); do not provide both.
io.kestra.plugin.kestra.AbstractKestraTask-Auth
API token for bearer auth
trueAutomatically retrieve credentials from Kestra's configuration if available
The default configuration can be configured globally inside the Kestra configuration file:
- Set
kestra.tasks.sdk.authentication.api-tokento use an API token - Set
kestra.tasks.sdk.authentication.usernameandkestra.tasks.sdk.authentication.passwordfor HTTP basic authentication - Set
kestra.tasks.sdk.authentication.urlto also default the Kestra API endpoint (seekestraUrlabove) The Enterprise edition also provides setting a default configuration at the Namespace or Tenant level by an administrator. Set to false to also opt out of the default URL.
Password for HTTP Basic auth
Username for HTTP Basic auth
isDefault booleanstring
Whether this role is the default role for new users
kestraUrl string
Override Kestra API endpoint
URL used for calls to the Kestra API. When null, falls back to the url configured alongside the default SDK authentication (Namespace or Tenant level, Enterprise edition), then renders {{ kestra.url }} from configuration; if still empty, defaults to http://localhost: 8080. Trailing slashes are stripped before use.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
roleDescription string
Role description
tenantId string
Override target tenant
Tenant identifier applied to API calls; defaults to the current execution tenant.
Outputs
id string
ID of the created or updated role