import * as pulumi from "@pulumi/pulumi"; /** * Resource for managing an exclusive set of AWS VPC Security Group Rules. * * This resource manages the complete set of ingress and egress rules assigned to a security group. It provides exclusive control by removing any rules not explicitly defined in the configuration. * * > This resource takes exclusive ownership over ingress and egress rules assigned to a security group. This includes removal of rules which are not explicitly configured. To prevent persistent drift, ensure any `aws.vpc.SecurityGroupIngressRule` and `aws.vpc.SecurityGroupEgressRule` resources managed alongside this resource are included in the `ingressRuleIds` and `egressRuleIds` arguments. * * > Destruction of this resource means Terraform will no longer manage reconciliation of the configured security group rules. It **will not** revoke the configured rules from the security group. * * > When this resource detects a configured rule ID which must be created, a warning diagnostic is emitted. This is due to a limitation in the [`AuthorizeSecurityGroupEgress`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeSecurityGroupEgress.html) and [`AuthorizeSecurityGroupIngress`](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_AuthorizeSecurityGroupIngress.html) APIs, which require the full rule definition to be provided rather than a reference to an existing rule ID. * * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.ec2.Vpc("example", {cidrBlock: "10.0.0.0/16"}); * const exampleSecurityGroup = new aws.ec2.SecurityGroup("example", { * name: "example", * vpcId: example.id, * }); * const exampleSecurityGroupIngressRule = new aws.vpc.SecurityGroupIngressRule("example", { * securityGroupId: exampleSecurityGroup.id, * cidrIpv4: "10.0.0.0/8", * fromPort: 80, * toPort: 80, * ipProtocol: "tcp", * }); * const exampleSecurityGroupEgressRule = new aws.vpc.SecurityGroupEgressRule("example", { * securityGroupId: exampleSecurityGroup.id, * cidrIpv4: "0.0.0.0/0", * ipProtocol: "-1", * }); * const exampleVpcSecurityGroupRulesExclusive = new aws.ec2.VpcSecurityGroupRulesExclusive("example", { * securityGroupId: exampleSecurityGroup.id, * ingressRuleIds: [exampleSecurityGroupIngressRule.id], * egressRuleIds: [exampleSecurityGroupEgressRule.id], * }); * ``` * * ### Disallow All Rules * * To automatically remove any configured security group rules, set both `ingressRuleIds` and `egressRuleIds` to empty lists. * * > This will not __prevent__ rules from being assigned to a security group via Terraform (or any other interface). This resource enables bringing security group rule assignments into a configured state, however, this reconciliation happens only when `apply` is proactively run. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.ec2.VpcSecurityGroupRulesExclusive("example", { * securityGroupId: exampleAwsSecurityGroup.id, * ingressRuleIds: [], * egressRuleIds: [], * }); * ``` * * ## Import * * Using `pulumi import`, import exclusive management of security group rules using the `securityGroupId`. For example: * * ```sh * $ pulumi import aws:ec2/vpcSecurityGroupRulesExclusive:VpcSecurityGroupRulesExclusive example sg-1234567890abcdef0 * ``` */ export declare class VpcSecurityGroupRulesExclusive extends pulumi.CustomResource { /** * Get an existing VpcSecurityGroupRulesExclusive resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: VpcSecurityGroupRulesExclusiveState, opts?: pulumi.CustomResourceOptions): VpcSecurityGroupRulesExclusive; /** * Returns true if the given object is an instance of VpcSecurityGroupRulesExclusive. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is VpcSecurityGroupRulesExclusive; /** * Egress rule IDs. */ readonly egressRuleIds: pulumi.Output; /** * Ingress rule IDs. */ readonly ingressRuleIds: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * ID of the security group. */ readonly securityGroupId: pulumi.Output; /** * Create a VpcSecurityGroupRulesExclusive resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: VpcSecurityGroupRulesExclusiveArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering VpcSecurityGroupRulesExclusive resources. */ export interface VpcSecurityGroupRulesExclusiveState { /** * Egress rule IDs. */ egressRuleIds?: pulumi.Input[] | undefined>; /** * Ingress rule IDs. */ ingressRuleIds?: pulumi.Input[] | undefined>; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ID of the security group. */ securityGroupId?: pulumi.Input; } /** * The set of arguments for constructing a VpcSecurityGroupRulesExclusive resource. */ export interface VpcSecurityGroupRulesExclusiveArgs { /** * Egress rule IDs. */ egressRuleIds: pulumi.Input[]>; /** * Ingress rule IDs. */ ingressRuleIds: pulumi.Input[]>; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ID of the security group. */ securityGroupId: pulumi.Input; } //# sourceMappingURL=vpcSecurityGroupRulesExclusive.d.ts.map