import * as pulumi from "@pulumi/pulumi"; /** * Provides an IAM OpenID Connect provider. * * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const _default = new aws.iam.OpenIdConnectProvider("default", { * url: "https://accounts.google.com", * clientIdLists: ["266362248691-342342xasdasdasda-apps.googleusercontent.com"], * thumbprintLists: ["cf23df2207d99a74fbe169e3eba035e633b65d94"], * }); * ``` * * ### Without A Thumbprint * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const _default = new aws.iam.OpenIdConnectProvider("default", { * url: "https://accounts.google.com", * clientIdLists: ["266362248691-342342xasdasdasda-apps.googleusercontent.com"], * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `arn` (String) ARN of the IAM OpenID Connect provider. * * Using `pulumi import`, import IAM OpenID Connect Providers using the `arn`. For example: * * ```sh * $ pulumi import aws:iam/openIdConnectProvider:OpenIdConnectProvider default arn:aws:iam::123456789012:oidc-provider/accounts.google.com * ``` */ export declare class OpenIdConnectProvider extends pulumi.CustomResource { /** * Get an existing OpenIdConnectProvider resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: OpenIdConnectProviderState, opts?: pulumi.CustomResourceOptions): OpenIdConnectProvider; /** * Returns true if the given object is an instance of OpenIdConnectProvider. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is OpenIdConnectProvider; /** * ARN assigned by AWS for this provider. */ readonly arn: pulumi.Output; /** * List of client IDs (audiences) that identify the application registered with the OpenID Connect provider. This is the value sent as the `clientId` parameter in OAuth requests. */ readonly clientIdLists: pulumi.Output; /** * Map of resource tags for the IAM OIDC provider. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; /** * List of server certificate thumbprints for the OpenID Connect (OIDC) identity provider's server certificate(s). For certain OIDC identity providers (e.g., Auth0, GitHub, GitLab, Google, or those using an Amazon S3-hosted JWKS endpoint), AWS relies on its own library of trusted root certificate authorities (CAs) for validation instead of using any configured thumbprints. In these cases, any configured `thumbprintList` is retained in the configuration but not used for verification. For other IdPs, if no `thumbprintList` is provided, IAM automatically retrieves and uses the top intermediate CA thumbprint from the OIDC IdP server certificate. However, if a `thumbprintList` is initially configured and later removed, Terraform does not prompt IAM to retrieve a thumbprint the same way. Instead, it continues using the original thumbprint list from the initial configuration. This differs from the behavior when creating an `aws.iam.OpenIdConnectProvider` without a `thumbprintList`. */ readonly thumbprintLists: pulumi.Output; /** * URL of the identity provider, corresponding to the `iss` claim. */ readonly url: pulumi.Output; /** * Create a OpenIdConnectProvider resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: OpenIdConnectProviderArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering OpenIdConnectProvider resources. */ export interface OpenIdConnectProviderState { /** * ARN assigned by AWS for this provider. */ arn?: pulumi.Input; /** * List of client IDs (audiences) that identify the application registered with the OpenID Connect provider. This is the value sent as the `clientId` parameter in OAuth requests. */ clientIdLists?: pulumi.Input[] | undefined>; /** * Map of resource tags for the IAM OIDC provider. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * List of server certificate thumbprints for the OpenID Connect (OIDC) identity provider's server certificate(s). For certain OIDC identity providers (e.g., Auth0, GitHub, GitLab, Google, or those using an Amazon S3-hosted JWKS endpoint), AWS relies on its own library of trusted root certificate authorities (CAs) for validation instead of using any configured thumbprints. In these cases, any configured `thumbprintList` is retained in the configuration but not used for verification. For other IdPs, if no `thumbprintList` is provided, IAM automatically retrieves and uses the top intermediate CA thumbprint from the OIDC IdP server certificate. However, if a `thumbprintList` is initially configured and later removed, Terraform does not prompt IAM to retrieve a thumbprint the same way. Instead, it continues using the original thumbprint list from the initial configuration. This differs from the behavior when creating an `aws.iam.OpenIdConnectProvider` without a `thumbprintList`. */ thumbprintLists?: pulumi.Input[] | undefined>; /** * URL of the identity provider, corresponding to the `iss` claim. */ url?: pulumi.Input; } /** * The set of arguments for constructing a OpenIdConnectProvider resource. */ export interface OpenIdConnectProviderArgs { /** * List of client IDs (audiences) that identify the application registered with the OpenID Connect provider. This is the value sent as the `clientId` parameter in OAuth requests. */ clientIdLists: pulumi.Input[]>; /** * Map of resource tags for the IAM OIDC provider. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * List of server certificate thumbprints for the OpenID Connect (OIDC) identity provider's server certificate(s). For certain OIDC identity providers (e.g., Auth0, GitHub, GitLab, Google, or those using an Amazon S3-hosted JWKS endpoint), AWS relies on its own library of trusted root certificate authorities (CAs) for validation instead of using any configured thumbprints. In these cases, any configured `thumbprintList` is retained in the configuration but not used for verification. For other IdPs, if no `thumbprintList` is provided, IAM automatically retrieves and uses the top intermediate CA thumbprint from the OIDC IdP server certificate. However, if a `thumbprintList` is initially configured and later removed, Terraform does not prompt IAM to retrieve a thumbprint the same way. Instead, it continues using the original thumbprint list from the initial configuration. This differs from the behavior when creating an `aws.iam.OpenIdConnectProvider` without a `thumbprintList`. */ thumbprintLists?: pulumi.Input[] | undefined>; /** * URL of the identity provider, corresponding to the `iss` claim. */ url: pulumi.Input; } //# sourceMappingURL=openIdConnectProvider.d.ts.map