import * as pulumi from "@pulumi/pulumi"; /** * Resource for maintaining exclusive management of principal and resource associations for an AWS RAM (Resource Access Manager) Resource Share. * * > This resource takes exclusive ownership over principal and resource associations for a resource share. This includes removal of principals and resources which are not explicitly configured. * * > Destruction of this resource will disassociate all configured principals and resources from the resource share. * * > **NOTE:** This resource cannot be used in conjunction with `aws.ram.PrincipalAssociation` or `aws.ram.ResourceAssociation` for the same resource share. Using them together will cause persistent drift and conflicts. * * ## Example Usage * * ### Basic Usage with Principals * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.ram.ResourceShare("example", { * name: "example", * allowExternalPrincipals: true, * }); * const exampleVpc = new aws.ec2.Vpc("example", {cidrBlock: "10.0.0.0/16"}); * const exampleSubnet = new aws.ec2.Subnet("example", { * vpcId: exampleVpc.id, * cidrBlock: "10.0.1.0/24", * }); * const exampleResourceShareAssociationsExclusive = new aws.ram.ResourceShareAssociationsExclusive("example", { * resourceShareArn: example.arn, * principals: [ * "111111111111", * "222222222222", * ], * resourceArns: [exampleSubnet.arn], * }); * ``` * * ### With Organization Principal * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * import * as std from "@pulumi/std"; * * const example = new aws.ram.ResourceShare("example", {name: "example"}); * const exampleVpc = new aws.ec2.Vpc("example", {cidrBlock: "10.0.0.0/16"}); * const exampleSubnet: aws.ec2.Subnet[] = []; * for (let range = 0; range < 2; range++) { * exampleSubnet.push(new aws.ec2.Subnet(`example-${range}`, { * vpcId: exampleVpc.id, * cidrBlock: std.cidrsubnetOutput({ * input: exampleVpc.cidrBlock, * newbits: 8, * netnum: range, * }).result, * })); * } * const exampleResourceShareAssociationsExclusive = new aws.ram.ResourceShareAssociationsExclusive("example", { * resourceShareArn: example.arn, * principals: [exampleAwsOrganizationsOrganization.arn], * resourceArns: exampleSubnet.map(__item => __item.arn), * }); * ``` * * ### With Service Principals * * When sharing resources with AWS services, use service principals. Service principals follow the pattern `service-id.amazonaws.com` (e.g., `pca-connector-ad.amazonaws.com`, `elasticmapreduce.amazonaws.com`). The `sources` argument can be used to restrict which AWS accounts the service can access the shared resources from. * * > **NOTE:** Service principals cannot be mixed with other principal types (AWS account IDs, organization ARNs, OU ARNs, IAM role ARNs, or IAM user ARNs) in the same resource. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.ram.ResourceShare("example", { * name: "example-service-share", * allowExternalPrincipals: true, * }); * const exampleCertificateAuthority = new aws.acmpca.CertificateAuthority("example", { * certificateAuthorityConfiguration: { * subject: { * commonName: "example.com", * }, * keyAlgorithm: "RSA_4096", * signingAlgorithm: "SHA512WITHRSA", * }, * type: "ROOT", * }); * const exampleResourceShareAssociationsExclusive = new aws.ram.ResourceShareAssociationsExclusive("example", { * resourceShareArn: example.arn, * principals: ["pca-connector-ad.amazonaws.com"], * resourceArns: [exampleCertificateAuthority.arn], * sources: [ * "111111111111", * "222222222222", * ], * }); * ``` * * ### Disallow All Associations * * To automatically remove any configured associations, omit the `principals` and `resourceArns` arguments or set them to empty lists. * * > This will not **prevent** associations from being created via Terraform (or any other interface). This resource enables bringing associations into a configured state, however, this reconciliation happens only when `apply` is proactively run. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.ram.ResourceShareAssociationsExclusive("example", {resourceShareArn: exampleAwsRamResourceShare.arn}); * ``` * * ## Import * * ### Identity Schema * * #### Required * * - `resourceShareArn` (String) ARN of the RAM resource share. * * Using `pulumi import`, import RAM Resource Share Association Exclusive using the `resourceShareArn`. For example: * * ```sh * $ pulumi import aws:ram/resourceShareAssociationsExclusive:ResourceShareAssociationsExclusive example arn:aws:ram:eu-west-1:123456789012:resource-share/73da1ab9-b94a-4ba3-8eb4-45917f7f4b12 * ``` */ export declare class ResourceShareAssociationsExclusive extends pulumi.CustomResource { /** * Get an existing ResourceShareAssociationsExclusive resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: ResourceShareAssociationsExclusiveState, opts?: pulumi.CustomResourceOptions): ResourceShareAssociationsExclusive; /** * Returns true if the given object is an instance of ResourceShareAssociationsExclusive. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is ResourceShareAssociationsExclusive; /** * Set of principals to associate with the resource share. Principals not configured in this argument will be removed. Valid values include: AWS account ID (exactly 12 digits, e.g., `123456789012`), AWS Organizations Organization ARN (e.g., `arn:aws:organizations::123456789012:organization/o-exampleorgid`), AWS Organizations Organizational Unit ARN (e.g., `arn:aws:organizations::123456789012:ou/o-exampleorgid/ou-examplerootid-exampleouid`), IAM role ARN (e.g., `arn:aws:iam::123456789012:role/example-role`), IAM user ARN (e.g., `arn:aws:iam::123456789012:user/example-user`), or service principal (e.g., `ec2.amazonaws.com`). */ readonly principals: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * Set of ARNs of resources to associate with the resource share. Resources not configured in this argument will be removed. */ readonly resourceArns: pulumi.Output; /** * ARN of the resource share. Changing this value forces creation of a new resource. */ readonly resourceShareArn: pulumi.Output; /** * Set of AWS account IDs that restrict which accounts a service principal can access resources from. This argument can only be specified when `principals` contains only service principals. When specified, it limits the source accounts from which the service can access the shared resources. */ readonly sources: pulumi.Output; /** * Create a ResourceShareAssociationsExclusive resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: ResourceShareAssociationsExclusiveArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering ResourceShareAssociationsExclusive resources. */ export interface ResourceShareAssociationsExclusiveState { /** * Set of principals to associate with the resource share. Principals not configured in this argument will be removed. Valid values include: AWS account ID (exactly 12 digits, e.g., `123456789012`), AWS Organizations Organization ARN (e.g., `arn:aws:organizations::123456789012:organization/o-exampleorgid`), AWS Organizations Organizational Unit ARN (e.g., `arn:aws:organizations::123456789012:ou/o-exampleorgid/ou-examplerootid-exampleouid`), IAM role ARN (e.g., `arn:aws:iam::123456789012:role/example-role`), IAM user ARN (e.g., `arn:aws:iam::123456789012:user/example-user`), or service principal (e.g., `ec2.amazonaws.com`). */ principals?: pulumi.Input[] | undefined>; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Set of ARNs of resources to associate with the resource share. Resources not configured in this argument will be removed. */ resourceArns?: pulumi.Input[] | undefined>; /** * ARN of the resource share. Changing this value forces creation of a new resource. */ resourceShareArn?: pulumi.Input; /** * Set of AWS account IDs that restrict which accounts a service principal can access resources from. This argument can only be specified when `principals` contains only service principals. When specified, it limits the source accounts from which the service can access the shared resources. */ sources?: pulumi.Input[] | undefined>; } /** * The set of arguments for constructing a ResourceShareAssociationsExclusive resource. */ export interface ResourceShareAssociationsExclusiveArgs { /** * Set of principals to associate with the resource share. Principals not configured in this argument will be removed. Valid values include: AWS account ID (exactly 12 digits, e.g., `123456789012`), AWS Organizations Organization ARN (e.g., `arn:aws:organizations::123456789012:organization/o-exampleorgid`), AWS Organizations Organizational Unit ARN (e.g., `arn:aws:organizations::123456789012:ou/o-exampleorgid/ou-examplerootid-exampleouid`), IAM role ARN (e.g., `arn:aws:iam::123456789012:role/example-role`), IAM user ARN (e.g., `arn:aws:iam::123456789012:user/example-user`), or service principal (e.g., `ec2.amazonaws.com`). */ principals?: pulumi.Input[] | undefined>; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * Set of ARNs of resources to associate with the resource share. Resources not configured in this argument will be removed. */ resourceArns?: pulumi.Input[] | undefined>; /** * ARN of the resource share. Changing this value forces creation of a new resource. */ resourceShareArn: pulumi.Input; /** * Set of AWS account IDs that restrict which accounts a service principal can access resources from. This argument can only be specified when `principals` contains only service principals. When specified, it limits the source accounts from which the service can access the shared resources. */ sources?: pulumi.Input[] | undefined>; } //# sourceMappingURL=resourceShareAssociationsExclusive.d.ts.map