import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Resource for managing exclusive AWS SSO Admin Customer Managed Policy Attachments. * * This resource is designed to manage all customer managed policy attachments for an SSO permission set. Using this resource, Terraform will remove any customer managed policies attached to the permission set that are not defined in the configuration. * * > **WARNING:** Do not use this resource together with the `aws.ssoadmin.CustomerManagedPolicyAttachment` resource for the same permission set. Doing so will cause a conflict and will lead to customer managed policies being removed. * * > Destruction of this resource means Terraform will no longer manage the customer managed policy attachments, **but will not detach any policies**. The permission set will retain all customer managed policies that were attached at the time of destruction. * * ## Example Usage * * ### Basic Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = aws.ssoadmin.getInstances({}); * const examplePermissionSet = new aws.ssoadmin.PermissionSet("example", { * name: "Example", * instanceArn: example.then(example => example.arns?.[0]), * }); * const examplePolicy = new aws.iam.Policy("example", { * name: "TestPolicy", * description: "My test policy", * policy: JSON.stringify({ * Version: "2012-10-17", * Statement: [{ * Action: ["ec2:Describe*"], * Effect: "Allow", * Resource: "*", * }], * }), * }); * const exampleCustomerManagedPolicyAttachmentsExclusive = new aws.ssoadmin.CustomerManagedPolicyAttachmentsExclusive("example", { * customerManagedPolicyReferences: [{ * name: examplePolicy.name, * path: "/", * }], * instanceArn: example.then(example => example.arns?.[0]), * permissionSetArn: examplePermissionSet.arn, * }); * ``` * * ### Disallow Customer Managed Policy Attachments * * To disallow all customer managed policy attachments, omit the `customerManagedPolicyReference` block. * * > Any customer managed policies attached to the permission set will be **removed**. * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.ssoadmin.CustomerManagedPolicyAttachmentsExclusive("example", { * instanceArn: exampleAwsSsoadminInstances.arns[0], * permissionSetArn: exampleAwsSsoadminPermissionSet.arn, * }); * ``` * * ## Import * * ### Identity Schema * * #### Required * * * `instanceArn` (String) ARN of the SSO Instance. * * `permissionSetArn` (String) ARN of the Permission Set. * * #### Optional * * * `accountId` (String) Account ID where this resource is managed. * * `region` (String) Region where this resource is managed. * * Using `pulumi import`, import SSO Admin Customer Managed Policy Attachments Exclusive using the `instanceArn` and `permissionSetArn` arguments, separated by a comma (`,`). For example: * * ```sh * $ pulumi import aws:ssoadmin/customerManagedPolicyAttachmentsExclusive:CustomerManagedPolicyAttachmentsExclusive example arn:aws:sso:::instance/ssoins-1234567890abcdef,arn:aws:sso:::permissionSet/ssoins-1234567890abcdef/ps-1234567890abcdef * ``` */ export declare class CustomerManagedPolicyAttachmentsExclusive extends pulumi.CustomResource { /** * Get an existing CustomerManagedPolicyAttachmentsExclusive resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: CustomerManagedPolicyAttachmentsExclusiveState, opts?: pulumi.CustomResourceOptions): CustomerManagedPolicyAttachmentsExclusive; /** * Returns true if the given object is an instance of CustomerManagedPolicyAttachmentsExclusive. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is CustomerManagedPolicyAttachmentsExclusive; /** * Specifies the names and paths of the customer managed policies to attach. See Customer Managed Policy Reference below. */ readonly customerManagedPolicyReferences: pulumi.Output; /** * ARN of the SSO Instance. */ readonly instanceArn: pulumi.Output; /** * ARN of the Permission Set. * * The following arguments are optional: */ readonly permissionSetArn: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; readonly timeouts: pulumi.Output; /** * Create a CustomerManagedPolicyAttachmentsExclusive resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: CustomerManagedPolicyAttachmentsExclusiveArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering CustomerManagedPolicyAttachmentsExclusive resources. */ export interface CustomerManagedPolicyAttachmentsExclusiveState { /** * Specifies the names and paths of the customer managed policies to attach. See Customer Managed Policy Reference below. */ customerManagedPolicyReferences?: pulumi.Input[] | undefined>; /** * ARN of the SSO Instance. */ instanceArn?: pulumi.Input; /** * ARN of the Permission Set. * * The following arguments are optional: */ permissionSetArn?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; timeouts?: pulumi.Input; } /** * The set of arguments for constructing a CustomerManagedPolicyAttachmentsExclusive resource. */ export interface CustomerManagedPolicyAttachmentsExclusiveArgs { /** * Specifies the names and paths of the customer managed policies to attach. See Customer Managed Policy Reference below. */ customerManagedPolicyReferences?: pulumi.Input[] | undefined>; /** * ARN of the SSO Instance. */ instanceArn: pulumi.Input; /** * ARN of the Permission Set. * * The following arguments are optional: */ permissionSetArn: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; timeouts?: pulumi.Input; } //# sourceMappingURL=customerManagedPolicyAttachmentsExclusive.d.ts.map