import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages an AWS Bedrock AgentCore Gateway Rule. Rules define conditions and actions that control how requests are routed and processed through a gateway, including principal-based access control, path-based routing, weighted target routing, and configuration bundle overrides. Rules are evaluated in order of `priority` (lower numbers first). * * ## Example Usage * * ### Route to a Static Target * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.bedrock.AgentcoreGatewayRule("example", { * actions: [{ * routeToTarget: { * staticRoute: { * targetName: exampleAwsBedrockagentcoreGatewayTarget.name, * }, * }, * }], * gatewayIdentifier: exampleAwsBedrockagentcoreGateway.gatewayId, * priority: 100, * description: "Route all requests to the primary target", * }); * ``` * * ### Weighted Route (Canary Traffic Split) * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const canary = new aws.bedrock.AgentcoreGatewayRule("canary", { * actions: [{ * routeToTarget: { * weightedRoute: { * trafficSplits: [ * { * name: "primary", * targetName: primary.name, * weight: 90, * }, * { * name: "canary", * targetName: canaryAwsBedrockagentcoreGatewayTarget.name, * weight: 10, * }, * ], * }, * }, * }], * gatewayIdentifier: example.gatewayId, * priority: 100, * }); * ``` * * ### Match on IAM Principals and Paths * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const current = aws.getCallerIdentity({}); * const currentGetPartition = aws.getPartition({}); * const restricted = new aws.bedrock.AgentcoreGatewayRule("restricted", { * actions: [{ * routeToTarget: { * staticRoute: { * targetName: example.name, * }, * }, * }], * conditions: [ * { * matchPrincipals: { * anyOfs: [{ * iamPrincipal: { * arn: Promise.all([currentGetPartition, current]).then(([currentGetPartition, current]) => `arn:${currentGetPartition.partition}:iam::${current.accountId}:role/agentcore-caller-*`), * operator: "StringLike", * }, * }], * }, * }, * { * matchPaths: { * anyOfs: ["/api/*"], * }, * }, * ], * gatewayIdentifier: exampleAwsBedrockagentcoreGateway.gatewayId, * priority: 50, * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * * `gatewayIdentifier` (String) Identifier of the gateway. * * `ruleId` (String) Identifier of the rule. * * #### Optional * * * `accountId` (String) AWS Account where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import gateway rules using `gatewayIdentifier` and `ruleId` separated by a comma (`,`). For example: * * ```sh * $ pulumi import aws:bedrock/agentcoreGatewayRule:AgentcoreGatewayRule example example-gateway-abcdef1234,11111111-2222-3333-4444-555555555555 * ``` */ export declare class AgentcoreGatewayRule extends pulumi.CustomResource { /** * Get an existing AgentcoreGatewayRule resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: AgentcoreGatewayRuleState, opts?: pulumi.CustomResourceOptions): AgentcoreGatewayRule; /** * Returns true if the given object is an instance of AgentcoreGatewayRule. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is AgentcoreGatewayRule; /** * One or two `action` blocks defining what happens when the rule's conditions match. See Action below. */ readonly actions: pulumi.Output; /** * Up to two `condition` blocks that must all be satisfied for the rule's actions to apply. See Condition below. */ readonly conditions: pulumi.Output; /** * Description of the rule. Between 1 and 256 characters. */ readonly description: pulumi.Output; /** * ARN of the gateway that owns the rule. */ readonly gatewayArn: pulumi.Output; /** * Identifier of the gateway to attach the rule to. */ readonly gatewayIdentifier: pulumi.Output; /** * Priority of the rule, between 1 and 1000000. Rules are evaluated in ascending order of priority. * * The following arguments are optional: */ readonly priority: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Identifier of the rule. */ readonly ruleId: pulumi.Output; /** * Present when the rule is system-managed. See `system` Block below. */ readonly systems: pulumi.Output; readonly timeouts: pulumi.Output; /** * Create a AgentcoreGatewayRule resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: AgentcoreGatewayRuleArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering AgentcoreGatewayRule resources. */ export interface AgentcoreGatewayRuleState { /** * One or two `action` blocks defining what happens when the rule's conditions match. See Action below. */ actions?: pulumi.Input[] | undefined>; /** * Up to two `condition` blocks that must all be satisfied for the rule's actions to apply. See Condition below. */ conditions?: pulumi.Input[] | undefined>; /** * Description of the rule. Between 1 and 256 characters. */ description?: pulumi.Input; /** * ARN of the gateway that owns the rule. */ gatewayArn?: pulumi.Input; /** * Identifier of the gateway to attach the rule to. */ gatewayIdentifier?: pulumi.Input; /** * Priority of the rule, between 1 and 1000000. Rules are evaluated in ascending order of priority. * * The following arguments are optional: */ priority?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Identifier of the rule. */ ruleId?: pulumi.Input; /** * Present when the rule is system-managed. See `system` Block below. */ systems?: pulumi.Input[] | undefined>; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a AgentcoreGatewayRule resource. */ export interface AgentcoreGatewayRuleArgs { /** * One or two `action` blocks defining what happens when the rule's conditions match. See Action below. */ actions?: pulumi.Input[] | undefined>; /** * Up to two `condition` blocks that must all be satisfied for the rule's actions to apply. See Condition below. */ conditions?: pulumi.Input[] | undefined>; /** * Description of the rule. Between 1 and 256 characters. */ description?: pulumi.Input; /** * Identifier of the gateway to attach the rule to. */ gatewayIdentifier: pulumi.Input; /** * Priority of the rule, between 1 and 1000000. Rules are evaluated in ascending order of priority. * * The following arguments are optional: */ priority: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; timeouts?: pulumi.Input; } //# sourceMappingURL=agentcoreGatewayRule.d.ts.map