import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Manages an AWS Bedrock AgentCore Policy. A Policy attaches Cedar authorization rules to a Policy Engine, which evaluates them at runtime to control agent access to resources. * * ## Example Usage * * ### Cedar Policy * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.bedrock.AgentcorePolicy("example", { * definition: { * cedar: { * statement: "permit(principal, action == Action::\\\"Read\\\", resource);\n", * }, * }, * name: "example_policy", * policyEngineId: exampleAwsBedrockagentcorePolicyEngine.policyEngineId, * description: "Allow read access to example resources", * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `policyEngineId` (String) ID of the policy engine. * - `policyId` (String) ID of the policy. * * #### Optional * * * `accountId` (String) AWS Account where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import Bedrock AgentCore Policies using the `policyEngineId` and `policyId` separated by a comma. For example: * * ```sh * $ pulumi import aws:bedrock/agentcorePolicy:AgentcorePolicy example PolicyEngine_i2fo6-dyqwrzl954,policy_ar2c3-o_rospxr2j * ``` */ export declare class AgentcorePolicy extends pulumi.CustomResource { /** * Get an existing AgentcorePolicy resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: AgentcorePolicyState, opts?: pulumi.CustomResourceOptions): AgentcorePolicy; /** * Returns true if the given object is an instance of AgentcorePolicy. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is AgentcorePolicy; /** * Policy definition. See `definition` Block for details. */ readonly definition: pulumi.Output; /** * Description of the policy. */ readonly description: pulumi.Output; /** * Name of the policy. Must be 1-48 characters and match the pattern `^[A-Za-z][A-Za-z0-9_]*$`. Changing this forces a new resource to be created. */ readonly name: pulumi.Output; /** * ARN of the Policy. */ readonly policyArn: pulumi.Output; /** * Identifier of the Policy Engine that owns this policy. Changing this forces a new resource to be created. * * The following arguments are optional: */ readonly policyEngineId: pulumi.Output; /** * Identifier of the Policy. */ readonly policyId: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; readonly timeouts: pulumi.Output; /** * Controls whether validation findings cause policy creation or update to fail. Valid values: `FAIL_ON_ANY_FINDINGS`, `IGNORE_ALL_FINDINGS`. Defaults to `FAIL_ON_ANY_FINDINGS`. */ readonly validationMode: pulumi.Output; /** * Create a AgentcorePolicy resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: AgentcorePolicyArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering AgentcorePolicy resources. */ export interface AgentcorePolicyState { /** * Policy definition. See `definition` Block for details. */ definition?: pulumi.Input; /** * Description of the policy. */ description?: pulumi.Input; /** * Name of the policy. Must be 1-48 characters and match the pattern `^[A-Za-z][A-Za-z0-9_]*$`. Changing this forces a new resource to be created. */ name?: pulumi.Input; /** * ARN of the Policy. */ policyArn?: pulumi.Input; /** * Identifier of the Policy Engine that owns this policy. Changing this forces a new resource to be created. * * The following arguments are optional: */ policyEngineId?: pulumi.Input; /** * Identifier of the Policy. */ policyId?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; timeouts?: pulumi.Input; /** * Controls whether validation findings cause policy creation or update to fail. Valid values: `FAIL_ON_ANY_FINDINGS`, `IGNORE_ALL_FINDINGS`. Defaults to `FAIL_ON_ANY_FINDINGS`. */ validationMode?: pulumi.Input; } /** * The set of arguments for constructing a AgentcorePolicy resource. */ export interface AgentcorePolicyArgs { /** * Policy definition. See `definition` Block for details. */ definition: pulumi.Input; /** * Description of the policy. */ description?: pulumi.Input; /** * Name of the policy. Must be 1-48 characters and match the pattern `^[A-Za-z][A-Za-z0-9_]*$`. Changing this forces a new resource to be created. */ name?: pulumi.Input; /** * Identifier of the Policy Engine that owns this policy. Changing this forces a new resource to be created. * * The following arguments are optional: */ policyEngineId: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; timeouts?: pulumi.Input; /** * Controls whether validation findings cause policy creation or update to fail. Valid values: `FAIL_ON_ANY_FINDINGS`, `IGNORE_ALL_FINDINGS`. Defaults to `FAIL_ON_ANY_FINDINGS`. */ validationMode?: pulumi.Input; } //# sourceMappingURL=agentcorePolicy.d.ts.map