import * as pulumi from "@pulumi/pulumi"; /** * Manages the complete IAM resource-based policy document for an AWS Lambda function, function version, or alias. * * > **Note:** `PutResourcePolicy` (used by this resource) replaces the *entire* resource-based policy on the Lambda resource, including any statements added with `aws.lambda.Permission`. Do not use `aws.lambda.ResourcePolicy` and `aws.lambda.Permission` on the same Lambda function, version, or alias — every apply of one will overwrite statements managed by the other. * * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const current = aws.getCallerIdentity({}); * const example = current.then(current => aws.iam.getPolicyDocument({ * statements: [{ * conditions: [{ * test: "StringEquals", * variable: "aws:SourceAccount", * values: [current.accountId], * }], * principals: [{ * type: "Service", * identifiers: ["s3.amazonaws.com"], * }], * sid: "AllowInvokeFromS3", * effect: "Allow", * actions: ["lambda:InvokeFunction"], * resources: [exampleAwsLambdaFunction.arn], * }], * })); * const exampleResourcePolicy = new aws.lambda.ResourcePolicy("example", { * resourceArn: exampleAwsLambdaFunction.arn, * policy: example.then(example => example.json), * }); * ``` * * ### Multiple Principals * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = aws.iam.getPolicyDocument({ * statements: [ * { * principals: [{ * type: "AWS", * identifiers: [ * "123456789012", * "210987654321", * ], * }], * sid: "AllowCrossAccountInvoke", * effect: "Allow", * actions: ["lambda:InvokeFunction"], * resources: [exampleAwsLambdaFunction.arn], * }, * { * conditions: [{ * test: "StringEquals", * variable: "aws:PrincipalOrgID", * values: ["o-1234567890"], * }], * principals: [{ * type: "AWS", * identifiers: ["*"], * }], * sid: "AllowOrganizationInvoke", * effect: "Allow", * actions: ["lambda:InvokeFunction"], * resources: [exampleAwsLambdaFunction.arn], * }, * ], * }); * const exampleResourcePolicy = new aws.lambda.ResourcePolicy("example", { * resourceArn: exampleAwsLambdaFunction.arn, * policy: example.then(example => example.json), * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `resourceArn` (String) ARN of the Lambda function, function version, or function alias. * * Using `pulumi import`, import Lambda policies using the `resourceArn`. For example: * * ```sh * $ pulumi import aws:lambda/resourcePolicy:ResourcePolicy example arn:aws:lambda:us-east-1:123456789012:function:example * ``` */ export declare class ResourcePolicy extends pulumi.CustomResource { /** * Get an existing ResourcePolicy resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: ResourcePolicyState, opts?: pulumi.CustomResourceOptions): ResourcePolicy; /** * Returns true if the given object is an instance of ResourcePolicy. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is ResourcePolicy; /** * JSON-formatted resource-based policy document to attach to the Lambda resource. This replaces the entire policy on the resource. Maximum 20,480 characters. */ readonly policy: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * ARN of the Lambda function, function version, or function alias to attach the policy to. Can be a qualified or unqualified ARN. */ readonly resourceArn: pulumi.Output; /** * Unique identifier for the current revision of the policy. */ readonly revisionId: pulumi.Output; /** * Create a ResourcePolicy resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: ResourcePolicyArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering ResourcePolicy resources. */ export interface ResourcePolicyState { /** * JSON-formatted resource-based policy document to attach to the Lambda resource. This replaces the entire policy on the resource. Maximum 20,480 characters. */ policy?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ARN of the Lambda function, function version, or function alias to attach the policy to. Can be a qualified or unqualified ARN. */ resourceArn?: pulumi.Input; /** * Unique identifier for the current revision of the policy. */ revisionId?: pulumi.Input; } /** * The set of arguments for constructing a ResourcePolicy resource. */ export interface ResourcePolicyArgs { /** * JSON-formatted resource-based policy document to attach to the Lambda resource. This replaces the entire policy on the resource. Maximum 20,480 characters. */ policy: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ARN of the Lambda function, function version, or function alias to attach the policy to. Can be a qualified or unqualified ARN. */ resourceArn: pulumi.Input; } //# sourceMappingURL=resourcePolicy.d.ts.map