
Kestra Plugin Set
CertifiedCreate or update a service account
Kestra Plugin Set
Create or update a service account
Upserts a service account by name: searches for an existing service account with the given name and updates it if found, or creates a new one otherwise.
type: io.kestra.plugin.kestra.ee.iam.serviceaccounts.SetExamples
Upsert a service account.
id: iam_service_account_set
namespace: company.team
tasks:
- id: upsert_service_account
type: io.kestra.plugin.kestra.ee.iam.serviceAccounts.Set
name: "etl-pipeline-sa"
serviceAccountDescription: "Service account for the ETL pipeline"
Properties
name *Requiredstring
Service account name
Name of the service account to create or update. Must match ^(?=.{1,63}$)[a-z0-9]+(?: -[a-z0-9]+)*$:
lowercase alphanumeric characters and hyphens only, starting and ending with an alphanumeric character,
maximum 63 characters.
auth Non-dynamic
Select API authentication
Use either an API token or HTTP Basic (username/password); do not provide both.
io.kestra.plugin.kestra.AbstractKestraTask-Auth
API token for bearer auth
trueAutomatically retrieve credentials from Kestra's configuration if available
The default configuration can be configured globally inside the Kestra configuration file:
- Set
kestra.tasks.sdk.authentication.api-tokento use an API token - Set
kestra.tasks.sdk.authentication.usernameandkestra.tasks.sdk.authentication.passwordfor HTTP basic authentication - Set
kestra.tasks.sdk.authentication.urlto also default the Kestra API endpoint (seekestraUrlabove) The Enterprise edition also provides setting a default configuration at the Namespace or Tenant level by an administrator. Set to false to also opt out of the default URL.
Password for HTTP Basic auth
Username for HTTP Basic auth
kestraUrl string
Override Kestra API endpoint
URL used for calls to the Kestra API. When null, falls back to the url configured alongside the default SDK authentication (Namespace or Tenant level, Enterprise edition), then renders {{ kestra.url }} from configuration; if still empty, defaults to http://localhost: 8080. Trailing slashes are stripped before use.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
serviceAccountDescription string
Service account description
tenantId string
Override target tenant
Tenant identifier applied to API calls; defaults to the current execution tenant.
Outputs
id string
ID of the created or updated service account