import type { MetadataBearer as __MetadataBearer } from "@smithy/types"; import type { CreatePolicyRequest, CreatePolicyResponse } from "../models/models_0"; /** * @public */ export type { __MetadataBearer }; /** * @public * * The input for {@link CreatePolicyCommand}. */ export interface CreatePolicyCommandInput extends CreatePolicyRequest { } /** * @public * * The output of {@link CreatePolicyCommand}. */ export interface CreatePolicyCommandOutput extends CreatePolicyResponse, __MetadataBearer { } declare const CreatePolicyCommand_base: { new (input: CreatePolicyCommandInput): import("@smithy/core/client").CommandImpl; new (input: CreatePolicyCommandInput): import("@smithy/core/client").CommandImpl; getEndpointParameterInstructions(): import("@smithy/types").EndpointParameterInstructions; }; /** *

Creates a policy of a specified type that you can attach to a root, an organizational * unit (OU), or an individual Amazon Web Services account.

*

For more information about policies and their use, see Managing * Organizations policies.

*

If the request includes tags, then the requester must have the * organizations:TagResource permission.

*

You can only call this operation from the management account or a member account that is a delegated administrator.

* @example * Use a bare-bones client and the command you need to make an API call. * ```javascript * import { OrganizationsClient, CreatePolicyCommand } from "@aws-sdk/client-organizations"; // ES Modules import * // const { OrganizationsClient, CreatePolicyCommand } = require("@aws-sdk/client-organizations"); // CommonJS import * // import type { OrganizationsClientConfig } from "@aws-sdk/client-organizations"; * const config = {}; // type is OrganizationsClientConfig * const client = new OrganizationsClient(config); * const input = { // CreatePolicyRequest * Content: "STRING_VALUE", // required * Description: "STRING_VALUE", // required * Name: "STRING_VALUE", // required * Type: "SERVICE_CONTROL_POLICY" || "RESOURCE_CONTROL_POLICY" || "TAG_POLICY" || "BACKUP_POLICY" || "AISERVICES_OPT_OUT_POLICY" || "CHATBOT_POLICY" || "DECLARATIVE_POLICY_EC2" || "SECURITYHUB_POLICY" || "INSPECTOR_POLICY" || "UPGRADE_ROLLOUT_POLICY" || "BEDROCK_POLICY" || "S3_POLICY" || "NETWORK_SECURITY_DIRECTOR_POLICY", // required * Tags: [ // Tags * { // Tag * Key: "STRING_VALUE", // required * Value: "STRING_VALUE", // required * }, * ], * }; * const command = new CreatePolicyCommand(input); * const response = await client.send(command); * // { // CreatePolicyResponse * // Policy: { // Policy * // PolicySummary: { // PolicySummary * // Id: "STRING_VALUE", * // Arn: "STRING_VALUE", * // Name: "STRING_VALUE", * // Description: "STRING_VALUE", * // Type: "SERVICE_CONTROL_POLICY" || "RESOURCE_CONTROL_POLICY" || "TAG_POLICY" || "BACKUP_POLICY" || "AISERVICES_OPT_OUT_POLICY" || "CHATBOT_POLICY" || "DECLARATIVE_POLICY_EC2" || "SECURITYHUB_POLICY" || "INSPECTOR_POLICY" || "UPGRADE_ROLLOUT_POLICY" || "BEDROCK_POLICY" || "S3_POLICY" || "NETWORK_SECURITY_DIRECTOR_POLICY", * // AwsManaged: true || false, * // }, * // Content: "STRING_VALUE", * // }, * // }; * * ``` * * @param CreatePolicyCommandInput - {@link CreatePolicyCommandInput} * @returns {@link CreatePolicyCommandOutput} * @see {@link CreatePolicyCommandInput} for command's `input` shape. * @see {@link CreatePolicyCommandOutput} for command's `response` shape. * @see {@link OrganizationsClientResolvedConfig | config} for OrganizationsClient's `config` shape. * * @throws {@link AccessDeniedException} (client fault) *

You don't have permissions to perform the requested operation. The user or role that * is making the request must have at least one IAM permissions policy attached that * grants the required permissions. For more information, see Access Management in the * IAM User Guide.

* * @throws {@link AWSOrganizationsNotInUseException} (client fault) *

Your account isn't a member of an organization. To make this request, you must use the * credentials of an account that belongs to an organization.

* * @throws {@link ConcurrentModificationException} (client fault) *

The target of the operation is currently being modified by a different request. Try * again later.

* * @throws {@link ConstraintViolationException} (client fault) *

Performing this operation violates a minimum or maximum value limit. For example, * attempting to remove the last service control policy (SCP) from an OU or root, inviting * or creating too many accounts to the organization, or attaching too many policies to an * account, OU, or root. This exception includes a reason that contains additional * information about the violated limit:

* *

Some of the reasons in the following list might not be applicable to this specific * API or operation.

*
* * * @throws {@link DuplicatePolicyException} (client fault) *

A policy with the same name already exists.

* * @throws {@link InvalidInputException} (client fault) *

The requested operation failed because you provided invalid values for one or more of * the request parameters. This exception includes a reason that contains additional * information about the violated limit:

* *

Some of the reasons in the following list might not be applicable to this specific * API or operation.

*
* * * @throws {@link MalformedPolicyDocumentException} (client fault) *

The provided policy document doesn't meet the requirements of the specified policy * type. For example, the syntax might be incorrect. For details about service control * policy syntax, see SCP syntax in the * Organizations User Guide.

* * @throws {@link PolicyTypeNotAvailableForOrganizationException} (client fault) *

You can't use the specified policy type with the feature set currently enabled for * this organization. For example, you can enable SCPs only after you enable all features * in the organization. For more information, see Managing * Organizations policiesin the Organizations User Guide.

* * @throws {@link ServiceException} (server fault) *

Organizations can't complete your request because of an internal service error. Try again * later.

* * @throws {@link TooManyRequestsException} (client fault) *

You have sent too many requests in too short a period of time. The quota helps protect * against denial-of-service attacks. Try again later.

*

For information about quotas that affect Organizations, see Quotas for Organizations in the * Organizations User Guide.

* * @throws {@link UnsupportedAPIEndpointException} (client fault) *

This action isn't available in the current Amazon Web Services Region.

* * @throws {@link OrganizationsServiceException} *

Base exception class for all service exceptions from Organizations service.

* * * @example To create a service control policy * ```javascript * // The following example shows how to create a service control policy (SCP) that is named AllowAllS3Actions. The JSON string in the content parameter specifies the content in the policy. The parameter string is escaped with backslashes to ensure that the embedded double quotes in the JSON policy are treated as literals in the parameter, which itself is surrounded by double quotes: * * * const input = { * Content: `{\"Version\":\"2012-10-17\",\"Statement\":{\"Effect\":\"Allow\",\"Action\":\"s3:*\"}}`, * Description: "Enables admins of attached accounts to delegate all S3 permissions", * Name: "AllowAllS3Actions", * Type: "SERVICE_CONTROL_POLICY" * }; * const command = new CreatePolicyCommand(input); * const response = await client.send(command); * /* response is * { * Policy: { * Content: `{"Version":"2012-10-17","Statement":{"Effect":"Allow","Action":"s3:*"}}`, * PolicySummary: { * Arn: "arn:aws:organizations::111111111111:policy/o-exampleorgid/service_control_policy/p-examplepolicyid111", * Description: "Allows delegation of all S3 actions", * Name: "AllowAllS3Actions", * Type: "SERVICE_CONTROL_POLICY" * } * } * } * *\/ * ``` * * @public */ export declare class CreatePolicyCommand extends CreatePolicyCommand_base { /** @internal type navigation helper, not in runtime. */ protected static __types: { api: { input: CreatePolicyRequest; output: CreatePolicyResponse; }; sdk: { input: CreatePolicyCommandInput; output: CreatePolicyCommandOutput; }; }; }