import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages an AWS Bedrock AgentCore OAuth2 Credential Provider. OAuth2 credential providers enable secure authentication with external OAuth2/OpenID Connect identity providers for agent runtimes. * * > **Note:** Write-Only arguments `clientIdWo` and `clientSecretWo` are available to use in place of `clientId` and `clientSecret`. Write-Only arguments are supported in HashiCorp Terraform 1.11.0 and later. Learn more. * * ## Example Usage * * ### GitHub OAuth Provider * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const github = new aws.bedrock.AgentcoreOauth2CredentialProvider("github", { * oauth2ProviderConfig: { * githubOauth2ProviderConfig: { * clientId: "your-github-client-id", * clientSecret: "your-github-client-secret", * }, * }, * name: "github-oauth-provider", * credentialProviderVendor: "GithubOauth2", * }); * ``` * * ### Custom OAuth Provider with Discovery URL * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const auth0 = new aws.bedrock.AgentcoreOauth2CredentialProvider("auth0", { * customOauth2ProviderConfig: [{ * custom: [{ * oauthDiscovery: [{ * discoveryUrl: "https://dev-company.auth0.com/.well-known/openid-configuration", * }], * clientIdWo: "auth0-client-id", * clientSecretWo: "auth0-client-secret", * clientCredentialsWoVersion: 1, * }], * }], * name: "auth0-oauth-provider", * credentialProviderVendor: "CustomOauth2", * }); * ``` * * ### Custom OAuth Provider with Authorization Server Metadata * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const keycloak = new aws.bedrock.AgentcoreOauth2CredentialProvider("keycloak", { * oauth2ProviderConfig: { * customOauth2ProviderConfig: { * oauthDiscovery: { * authorizationServerMetadata: { * issuer: "https://auth.company.com/realms/production", * authorizationEndpoint: "https://auth.company.com/realms/production/protocol/openid-connect/auth", * tokenEndpoint: "https://auth.company.com/realms/production/protocol/openid-connect/token", * responseTypes: [ * "code", * "id_token", * ], * tokenEndpointAuthMethods: ["client_secret_basic"], * }, * }, * clientIdWo: "keycloak-client-id", * clientSecretWo: "keycloak-client-secret", * clientCredentialsWoVersion: 1, * }, * }, * name: "keycloak-oauth-provider", * credentialProviderVendor: "CustomOauth2", * }); * ``` * * ## Import * * > **Note:** OAuth2 client credentials are input-only in the AgentCore API and are not returned by the read operation. On import, `clientId`, `clientSecret`, `clientSecretSource`, `clientSecretConfig`, and the write-only `clientIdWo`/`clientSecretWo`/`clientCredentialsWoVersion` arguments cannot be recovered from the service, so the first `pulumi preview` after import shows them as additions. Run `pulumi up` once to reconcile state from your configuration; subsequent plans are clean. * * ### Identity Schema * * #### Required * * * `name` (String) OAuth2 credential provider name. * * #### Optional * * * `accountId` (String) Account ID where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import Bedrock AgentCore OAuth2 Credential Provider using `name`. For example: * * ```sh * $ pulumi import aws:bedrock/agentcoreOauth2CredentialProvider:AgentcoreOauth2CredentialProvider example example-oauth2-provider * ``` */ export declare class AgentcoreOauth2CredentialProvider extends pulumi.CustomResource { /** * Get an existing AgentcoreOauth2CredentialProvider resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: AgentcoreOauth2CredentialProviderState, opts?: pulumi.CustomResourceOptions): AgentcoreOauth2CredentialProvider; /** * Returns true if the given object is an instance of AgentcoreOauth2CredentialProvider. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is AgentcoreOauth2CredentialProvider; /** * Callback URL to register on the OAuth2 credential provider as an allowed callback URL. This URL is where the OAuth2 authorization server redirects users after they complete the authorization flow. */ readonly callbackUrl: pulumi.Output; /** * ARN of the AWS Secrets Manager secret containing the client secret. See `clientSecretArn` Block below. */ readonly clientSecretArns: pulumi.Output; /** * ARN of the OAuth2 credential provider. */ readonly credentialProviderArn: pulumi.Output; /** * Vendor of the OAuth2 credential provider. Valid values include `CustomOauth2`, `GithubOauth2`, `GoogleOauth2`, `MicrosoftOauth2`, `SalesforceOauth2`, `SlackOauth2`, `AtlassianOauth2`, `LinkedinOauth2`, and a number of additional supported vendors (e.g. `XOauth2`, `FacebookOauth2`, `SpotifyOauth2`) configured via `includedOauth2ProviderConfig`. Refer to the AWS API for the full, current list. */ readonly credentialProviderVendor: pulumi.Output; /** * Name of the OAuth2 credential provider. */ readonly name: pulumi.Output; /** * OAuth2 provider configuration. Must contain exactly one provider type. See `oauth2ProviderConfig` Block below. * * The following arguments are optional: */ readonly oauth2ProviderConfig: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; readonly timeouts: pulumi.Output; /** * Create a AgentcoreOauth2CredentialProvider resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: AgentcoreOauth2CredentialProviderArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering AgentcoreOauth2CredentialProvider resources. */ export interface AgentcoreOauth2CredentialProviderState { /** * Callback URL to register on the OAuth2 credential provider as an allowed callback URL. This URL is where the OAuth2 authorization server redirects users after they complete the authorization flow. */ callbackUrl?: pulumi.Input; /** * ARN of the AWS Secrets Manager secret containing the client secret. See `clientSecretArn` Block below. */ clientSecretArns?: pulumi.Input[] | undefined>; /** * ARN of the OAuth2 credential provider. */ credentialProviderArn?: pulumi.Input; /** * Vendor of the OAuth2 credential provider. Valid values include `CustomOauth2`, `GithubOauth2`, `GoogleOauth2`, `MicrosoftOauth2`, `SalesforceOauth2`, `SlackOauth2`, `AtlassianOauth2`, `LinkedinOauth2`, and a number of additional supported vendors (e.g. `XOauth2`, `FacebookOauth2`, `SpotifyOauth2`) configured via `includedOauth2ProviderConfig`. Refer to the AWS API for the full, current list. */ credentialProviderVendor?: pulumi.Input; /** * Name of the OAuth2 credential provider. */ name?: pulumi.Input; /** * OAuth2 provider configuration. Must contain exactly one provider type. See `oauth2ProviderConfig` Block below. * * The following arguments are optional: */ oauth2ProviderConfig?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a AgentcoreOauth2CredentialProvider resource. */ export interface AgentcoreOauth2CredentialProviderArgs { /** * Vendor of the OAuth2 credential provider. Valid values include `CustomOauth2`, `GithubOauth2`, `GoogleOauth2`, `MicrosoftOauth2`, `SalesforceOauth2`, `SlackOauth2`, `AtlassianOauth2`, `LinkedinOauth2`, and a number of additional supported vendors (e.g. `XOauth2`, `FacebookOauth2`, `SpotifyOauth2`) configured via `includedOauth2ProviderConfig`. Refer to the AWS API for the full, current list. */ credentialProviderVendor: pulumi.Input; /** * Name of the OAuth2 credential provider. */ name?: pulumi.Input; /** * OAuth2 provider configuration. Must contain exactly one provider type. See `oauth2ProviderConfig` Block below. * * The following arguments are optional: */ oauth2ProviderConfig: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Key-value map of resource tags. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; timeouts?: pulumi.Input; } //# sourceMappingURL=agentcoreOauth2CredentialProvider.d.ts.map