import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Resource for managing an Amazon Aurora DSQL Cluster resource-based policy. * * > Aurora DSQL resource-based policies can grant access to principals within the same AWS account as the cluster. Cross-account access is not currently supported by Aurora DSQL resource-based policies. * * > Aurora DSQL resource-based policy changes are eventually consistent and typically take effect within one minute. * * ## Example Usage * * ### Block Public Internet Access * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.dsql.Cluster("example", {}); * const exampleClusterPolicy = new aws.dsql.ClusterPolicy("example", { * identifier: example.identifier, * policy: JSON.stringify({ * Version: "2012-10-17", * Statement: [{ * Sid: "DenyAccessFromOutsideVPC", * Effect: "Deny", * Principal: { * AWS: "*", * }, * Action: [ * "dsql:DbConnect", * "dsql:DbConnectAdmin", * ], * Resource: "*", * Condition: { * Null: { * "aws:SourceVpc": "true", * }, * }, * }], * }), * }); * ``` * * This policy denies `dsql:DbConnect` and `dsql:DbConnectAdmin` requests from the public internet. It only checks whether the request came from a VPC. To limit access to a specific VPC, use `aws:SourceVpc` with `StringNotEquals`. * * The calling principal still requires an identity-based IAM policy that allows the required Aurora DSQL actions on the cluster. * * ### Restrict Access to a Specific VPC * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.dsql.Cluster("example", {}); * const exampleClusterPolicy = new aws.dsql.ClusterPolicy("example", { * identifier: example.identifier, * policy: pulumi.jsonStringify({ * Version: "2012-10-17", * Statement: [{ * Sid: "DenyAccessFromOtherVPCs", * Effect: "Deny", * Principal: { * AWS: "*", * }, * Action: [ * "dsql:DbConnect", * "dsql:DbConnectAdmin", * ], * Resource: example.arn, * Condition: { * StringNotEquals: { * "aws:SourceVpc": exampleAwsVpc.id, * }, * }, * }], * }), * }); * ``` * * ### Restrict Access to an AWS Organization * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.dsql.Cluster("example", {}); * const exampleClusterPolicy = new aws.dsql.ClusterPolicy("example", { * identifier: example.identifier, * policy: pulumi.jsonStringify({ * Version: "2012-10-17", * Statement: [{ * Sid: "DenyAccessFromOutsideOrganization", * Effect: "Deny", * Principal: { * AWS: "*", * }, * Action: [ * "dsql:DbConnect", * "dsql:DbConnectAdmin", * ], * Resource: example.arn, * Condition: { * StringNotEquals: { * "aws:PrincipalOrgID": "o-exampleorgid", * }, * }, * }], * }), * }); * ``` * * For more examples, including specific organizational units and multi-Region cluster policies, see the [Aurora DSQL resource-based policy examples](https://docs.aws.amazon.com/aurora-dsql/latest/userguide/rbp-examples.html). * * ## Import * * ### Identity Schema * * #### Required * * * `identifier` (String) Identifier of the Aurora DSQL Cluster. * * #### Optional * * * `accountId` (String) AWS Account where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import Aurora DSQL Cluster Policies using the cluster `identifier`. For example: * * ```sh * $ pulumi import aws:dsql/clusterPolicy:ClusterPolicy example abcde1f234ghijklmnop5qr6st * ``` */ export declare class ClusterPolicy extends pulumi.CustomResource { /** * Get an existing ClusterPolicy resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: ClusterPolicyState, opts?: pulumi.CustomResourceOptions): ClusterPolicy; /** * Returns true if the given object is an instance of ClusterPolicy. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is ClusterPolicy; /** * Whether to bypass the policy lockout safety check. Setting this value to `true` increases the risk that the cluster becomes unmanageable. Defaults to `false`. */ readonly bypassPolicyLockoutSafetyCheck: pulumi.Output; /** * Identifier of the Aurora DSQL Cluster. */ readonly identifier: pulumi.Output; /** * Resource-based policy document as JSON. */ readonly policy: pulumi.Output; /** * Version of the policy document. */ readonly policyVersion: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; readonly timeouts: pulumi.Output; /** * Create a ClusterPolicy resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: ClusterPolicyArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering ClusterPolicy resources. */ export interface ClusterPolicyState { /** * Whether to bypass the policy lockout safety check. Setting this value to `true` increases the risk that the cluster becomes unmanageable. Defaults to `false`. */ bypassPolicyLockoutSafetyCheck?: pulumi.Input; /** * Identifier of the Aurora DSQL Cluster. */ identifier?: pulumi.Input; /** * Resource-based policy document as JSON. */ policy?: pulumi.Input; /** * Version of the policy document. */ policyVersion?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a ClusterPolicy resource. */ export interface ClusterPolicyArgs { /** * Whether to bypass the policy lockout safety check. Setting this value to `true` increases the risk that the cluster becomes unmanageable. Defaults to `false`. */ bypassPolicyLockoutSafetyCheck?: pulumi.Input; /** * Identifier of the Aurora DSQL Cluster. */ identifier: pulumi.Input; /** * Resource-based policy document as JSON. */ policy: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; timeouts?: pulumi.Input; } //# sourceMappingURL=clusterPolicy.d.ts.map