yandex_iam_workload_identity_federated_credential (Resource)
Written by
Updated at April 9, 2026
A federated credential.
Example usage
//
// Create a new IAM Workload Identity Federated Credential.
//
resource "yandex_iam_workload_identity_federated_credential" "fed_cred" {
service_account_id = "some_sa_id"
federation_id = "some_wli_federation_id"
external_subject_id = "some_external_subject_id"
}
Arguments & Attributes Reference
created_at(Read-Only) (String). Creation timestamp.external_subject_id(Required)(String). Id of the external subject.federated_credential_id(String). ID of the federated credential to return.
To get the federated credential ID, make a [FederatedCredentialService.List] request.federation_id(Required)(String). ID of the workload identity federation which is used for authentication.id(String). ID of the federated credential to return.
To get the federated credential ID, make a [FederatedCredentialService.List] request.service_account_id(String). Id of the service account that the federated credential belongs to.timeouts[Block].create(String). A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours).delete(String). A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Setting a timeout for a Delete operation is only applicable if changes are saved into state before the destroy operation occurs.read(String). A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours). Read operations occur during any refresh or planning operation when refresh is enabled.update(String). A string that can be parsed as a duration consisting of numbers and unit suffixes, such as "30s" or "2h45m". Valid time units are "s" (seconds), "m" (minutes), "h" (hours).
Import
The resource can be imported by using their resource ID. For getting it you can use Yandex Cloud Web Console
# terraform import yandex_iam_workload_identity_federated_credential.<resource Name> <resource Id>
terraform import yandex_iam_workload_identity_federated_credential.fed_cred ...