Kestra Plugin Set

Kestra Plugin Set

Certified

Create or update a role

Upserts a role by name: searches for an existing role with the given name and updates it if found, or creates a new one otherwise.

yaml
type: io.kestra.plugin.kestra.ee.iam.roles.Set

Upsert a role.

yaml
id: iam_role_set
namespace: company.team

tasks:
  - id: upsert_role
    type: io.kestra.plugin.kestra.ee.iam.roles.Set
    name: "data-engineer-role"
    roleDescription: "Role for data engineers"
    permissions:
      FLOW:
        - READ
        - CREATE
      EXECUTION:
        - READ
Properties

Role name

Role permissions

Map of resource type to list of allowed actions, e.g. {"FLOW": ["READ", "CREATE"], "EXECUTION": ["READ"]}. Valid resource types include: FLOW, BLUEPRINT, NAMESPACE, EXECUTION, USER, GROUP, ROLE, BINDING, AUDITLOG, SECRET, KVSTORE, SETTING, APP, ASSET, TEST, DASHBOARD, SERVICEACCOUNT, and others.

Select API authentication

Use either an API token or HTTP Basic (username/password); do not provide both.

Definitions
apiTokenstring

API token for bearer auth

autobooleanstring
Defaulttrue

Automatically retrieve credentials from Kestra's configuration if available

The default configuration can be configured globally inside the Kestra configuration file:

  • Set kestra.tasks.sdk.authentication.api-token to use an API token
  • Set kestra.tasks.sdk.authentication.username and kestra.tasks.sdk.authentication.password for HTTP basic authentication
  • Set kestra.tasks.sdk.authentication.url to also default the Kestra API endpoint (see kestraUrl above) The Enterprise edition also provides setting a default configuration at the Namespace or Tenant level by an administrator. Set to false to also opt out of the default URL.
passwordstring

Password for HTTP Basic auth

usernamestring

Username for HTTP Basic auth

Whether this role is the default role for new users

Override Kestra API endpoint

URL used for calls to the Kestra API. When null, falls back to the url configured alongside the default SDK authentication (Namespace or Tenant level, Enterprise edition), then renders {{ kestra.url }} from configuration; if still empty, defaults to http://localhost: 8080. Trailing slashes are stripped before use.

Reference (ref) of the pluginDefaults to apply to this task.

Role description

Override target tenant

Tenant identifier applied to API calls; defaults to the current execution tenant.

ID of the created or updated role