import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages an AWS Account Access Entitlement. An Entitlement grants an IAM Identity Center principal the ability to assume a specific IAM role in a target AWS account through an Account Access Application. * * > **Note:** Entitlements are immutable. Changing `applicationArn` or `entitlement` triggers replacement. * * > **Note:** The IAM role referenced by `entitlement.principal_role.role_arn` must have a trust policy that allows the Account Access service to assume it. The role's `assumeRolePolicy` must grant `sts:AssumeRole`, `sts:SetContext`, and `sts:TagSession` to the `account-access.amazonaws.com` service principal. Without `sts:TagSession`, credential retrieval for the entitlement fails. See the Complete Example below. * * ## Example Usage * * ### User Principal * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.accountaccess.Entitlement("example", { * entitlement: { * principalRole: { * principal: { * identityCenter: { * userId: "11111111-2222-3333-4444-555555555555", * }, * }, * roleArn: "arn:aws:iam::123456789012:role/Developer", * }, * }, * applicationArn: exampleAwsAccountaccessApplication.arn, * }); * ``` * * ### Group Principal * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.accountaccess.Entitlement("example", { * entitlement: { * principalRole: { * principal: { * identityCenter: { * groupId: "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee", * }, * }, * roleArn: "arn:aws:iam::123456789012:role/Engineering", * }, * }, * applicationArn: exampleAwsAccountaccessApplication.arn, * }); * ``` * * ### Complete Example * * The target IAM role must trust the Account Access service. This example provisions a role with the required trust policy and grants an entitlement to it. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = aws.ssoadmin.getInstances({}); * const exampleApplication = new aws.accountaccess.Application("example", {identitySource: { * identityCenter: { * instanceArn: example.then(example => example.arns?.[0]), * }, * }}); * // The target role must allow the Account Access service to assume it. * // sts:TagSession is required for credential retrieval to succeed. * const target = new aws.iam.Role("target", { * name: "example-account-access-developer", * assumeRolePolicy: JSON.stringify({ * Version: "2012-10-17", * Statement: [{ * Effect: "Allow", * Principal: { * Service: "account-access.amazonaws.com", * }, * Action: [ * "sts:AssumeRole", * "sts:SetContext", * "sts:TagSession", * ], * }], * }), * }); * const exampleEntitlement = new aws.accountaccess.Entitlement("example", { * entitlement: { * principalRole: { * principal: { * identityCenter: { * userId: "11111111-2222-3333-4444-555555555555", * }, * }, * roleArn: target.arn, * }, * }, * applicationArn: exampleApplication.arn, * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * * `applicationArn` (String) ARN of the parent Account Access Application. * * `entitlementId` (String) Service-assigned unique identifier for this Entitlement. * * #### Optional * * * `accountId` (String) AWS Account where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import Account Access Entitlements using the composite ID. For example: * * ```sh * $ pulumi import aws:accountaccess/entitlement:Entitlement example arn:aws:account-access:us-east-1:123456789012:application/aam-0123456789abcdef,ent-0123456789abcdef * ``` */ export declare class Entitlement extends pulumi.CustomResource { /** * Get an existing Entitlement resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: EntitlementState, opts?: pulumi.CustomResourceOptions): Entitlement; /** * Returns true if the given object is an instance of Entitlement. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is Entitlement; /** * ARN of the parent Account Access Application. Forces replacement when changed. */ readonly applicationArn: pulumi.Output; /** * Entitlement configuration. See `entitlement` Block below. * * The following arguments are optional: */ readonly entitlement: pulumi.Output; /** * Service-assigned unique identifier for this Entitlement. */ readonly entitlementId: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Create a Entitlement resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: EntitlementArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering Entitlement resources. */ export interface EntitlementState { /** * ARN of the parent Account Access Application. Forces replacement when changed. */ applicationArn?: pulumi.Input; /** * Entitlement configuration. See `entitlement` Block below. * * The following arguments are optional: */ entitlement?: pulumi.Input; /** * Service-assigned unique identifier for this Entitlement. */ entitlementId?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; } /** * The set of arguments for constructing a Entitlement resource. */ export interface EntitlementArgs { /** * ARN of the parent Account Access Application. Forces replacement when changed. */ applicationArn: pulumi.Input; /** * Entitlement configuration. See `entitlement` Block below. * * The following arguments are optional: */ entitlement: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; } //# sourceMappingURL=entitlement.d.ts.map