import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * Provides a AWS Transfer User resource. Managing SSH keys can be accomplished with the `aws.transfer.SshKey` resource. * * > **NOTE:** We suggest using `jsonencode()` or `aws.iam.getPolicyDocument` when assigning a value to `policy`. They seamlessly translate Terraform language into JSON, enabling you to maintain consistency within your configuration without the need for context switches. Also, you can sidestep potential complications arising from formatting discrepancies, whitespace inconsistencies, and other nuances inherent to JSON. * * ## Example Usage * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const fooServer = new aws.transfer.Server("foo", { * identityProviderType: "SERVICE_MANAGED", * tags: { * NAME: "tf-acc-test-transfer-server", * }, * }); * const assumeRole = aws.iam.getPolicyDocument({ * statements: [{ * principals: [{ * type: "Service", * identifiers: ["transfer.amazonaws.com"], * }], * effect: "Allow", * actions: ["sts:AssumeRole"], * }], * }); * const fooRole = new aws.iam.Role("foo", { * name: "tf-test-transfer-user-iam-role", * assumeRolePolicy: assumeRole.then(assumeRole => assumeRole.json), * }); * const foo = aws.iam.getPolicyDocument({ * statements: [{ * sid: "AllowFullAccesstoS3", * effect: "Allow", * actions: ["s3:*"], * resources: ["*"], * }], * }); * const fooRolePolicy = new aws.iam.RolePolicy("foo", { * name: "tf-test-transfer-user-iam-policy", * role: fooRole.id, * policy: foo.then(foo => foo.json), * }); * const fooUser = new aws.transfer.User("foo", { * homeDirectoryMappings: [{ * entry: "/test.pdf", * target: "/bucket3/test-path/tftestuser.pdf", * }], * serverId: fooServer.id, * userName: "tftestuser", * role: fooRole.arn, * homeDirectoryType: "LOGICAL", * }); * ``` * * To restrict a user to their own home directory, use a `homeDirectoryMappings` block like the following: * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as aws from "@pulumi/aws"; * * const example = new aws.transfer.User("example", { * homeDirectoryMappings: [{ * entry: "/", * target: `/${foo.id}/${Transfer:UserName}`, * }], * homeDirectoryType: "LOGICAL", * }); * ``` * * ## Import * * Using `pulumi import`, import Transfer Users using the `serverId` and `userName` separated by `/`. For example: * * ```sh * $ pulumi import aws:transfer/user:User bar s-12345678/test-username * ``` */ export declare class User extends pulumi.CustomResource { /** * Get an existing User resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: UserState, opts?: pulumi.CustomResourceOptions): User; /** * Returns true if the given object is an instance of User. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is User; /** * ARN of Transfer User */ readonly arn: pulumi.Output; /** * Landing directory (folder) for a user when they log in to the server using their SFTP client. It should begin with a `/`. The first item in the path is the name of the home bucket (accessible as `${Transfer:HomeBucket}` in the policy) and the rest is the home directory (accessible as `${Transfer:HomeDirectory}` in the policy). For example, `/example-bucket-1234/username` would set the home bucket to `example-bucket-1234` and the home directory to `username`. */ readonly homeDirectory: pulumi.Output; /** * Logical directory mappings that specify what S3 paths and keys should be visible to your user and how you want to make them visible. See `homeDirectoryMappings` Block below. */ readonly homeDirectoryMappings: pulumi.Output; /** * Type of landing directory (folder) you mapped for your users' home directory. Valid values are `PATH` and `LOGICAL`. */ readonly homeDirectoryType: pulumi.Output; /** * IAM JSON policy document that scopes down user access to portions of their Amazon S3 bucket. IAM variables you can use inside this policy include `${Transfer:UserName}`, `${Transfer:HomeDirectory}`, and `${Transfer:HomeBucket}`. Since the IAM variable syntax matches Terraform's interpolation syntax, they must be escaped inside Terraform configuration strings (`$${Transfer:UserName}`). These are evaluated on-the-fly when navigating the bucket. */ readonly policy: pulumi.Output; /** * Full POSIX identity, including user ID (Uid), group ID (Gid), and any secondary groups IDs (SecondaryGids), that controls your users' access to your Amazon EFS file systems. See `posixProfile` Block below. */ readonly posixProfile: pulumi.Output; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ readonly region: pulumi.Output; /** * ARN of an IAM role that allows the service to control your user’s access to your Amazon S3 bucket. */ readonly role: pulumi.Output; /** * Server ID of the Transfer Server (e.g., `s-12345678`) */ readonly serverId: pulumi.Output; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ readonly tags: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ readonly tagsAll: pulumi.Output<{ [key: string]: string; }>; /** * Name used for log in to your SFTP server. */ readonly userName: pulumi.Output; /** * Create a User resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: UserArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering User resources. */ export interface UserState { /** * ARN of Transfer User */ arn?: pulumi.Input; /** * Landing directory (folder) for a user when they log in to the server using their SFTP client. It should begin with a `/`. The first item in the path is the name of the home bucket (accessible as `${Transfer:HomeBucket}` in the policy) and the rest is the home directory (accessible as `${Transfer:HomeDirectory}` in the policy). For example, `/example-bucket-1234/username` would set the home bucket to `example-bucket-1234` and the home directory to `username`. */ homeDirectory?: pulumi.Input; /** * Logical directory mappings that specify what S3 paths and keys should be visible to your user and how you want to make them visible. See `homeDirectoryMappings` Block below. */ homeDirectoryMappings?: pulumi.Input[] | undefined>; /** * Type of landing directory (folder) you mapped for your users' home directory. Valid values are `PATH` and `LOGICAL`. */ homeDirectoryType?: pulumi.Input; /** * IAM JSON policy document that scopes down user access to portions of their Amazon S3 bucket. IAM variables you can use inside this policy include `${Transfer:UserName}`, `${Transfer:HomeDirectory}`, and `${Transfer:HomeBucket}`. Since the IAM variable syntax matches Terraform's interpolation syntax, they must be escaped inside Terraform configuration strings (`$${Transfer:UserName}`). These are evaluated on-the-fly when navigating the bucket. */ policy?: pulumi.Input; /** * Full POSIX identity, including user ID (Uid), group ID (Gid), and any secondary groups IDs (SecondaryGids), that controls your users' access to your Amazon EFS file systems. See `posixProfile` Block below. */ posixProfile?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ARN of an IAM role that allows the service to control your user’s access to your Amazon S3 bucket. */ role?: pulumi.Input; /** * Server ID of the Transfer Server (e.g., `s-12345678`) */ serverId?: pulumi.Input; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Map of tags assigned to the resource, including those inherited from the provider `defaultTags` configuration block. */ tagsAll?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Name used for log in to your SFTP server. */ userName?: pulumi.Input; } /** * The set of arguments for constructing a User resource. */ export interface UserArgs { /** * Landing directory (folder) for a user when they log in to the server using their SFTP client. It should begin with a `/`. The first item in the path is the name of the home bucket (accessible as `${Transfer:HomeBucket}` in the policy) and the rest is the home directory (accessible as `${Transfer:HomeDirectory}` in the policy). For example, `/example-bucket-1234/username` would set the home bucket to `example-bucket-1234` and the home directory to `username`. */ homeDirectory?: pulumi.Input; /** * Logical directory mappings that specify what S3 paths and keys should be visible to your user and how you want to make them visible. See `homeDirectoryMappings` Block below. */ homeDirectoryMappings?: pulumi.Input[] | undefined>; /** * Type of landing directory (folder) you mapped for your users' home directory. Valid values are `PATH` and `LOGICAL`. */ homeDirectoryType?: pulumi.Input; /** * IAM JSON policy document that scopes down user access to portions of their Amazon S3 bucket. IAM variables you can use inside this policy include `${Transfer:UserName}`, `${Transfer:HomeDirectory}`, and `${Transfer:HomeBucket}`. Since the IAM variable syntax matches Terraform's interpolation syntax, they must be escaped inside Terraform configuration strings (`$${Transfer:UserName}`). These are evaluated on-the-fly when navigating the bucket. */ policy?: pulumi.Input; /** * Full POSIX identity, including user ID (Uid), group ID (Gid), and any secondary groups IDs (SecondaryGids), that controls your users' access to your Amazon EFS file systems. See `posixProfile` Block below. */ posixProfile?: pulumi.Input; /** * Region where this resource will be [managed](https://docs.aws.amazon.com/general/latest/gr/rande.html#regional-endpoints). Defaults to the Region set in the provider configuration. */ region?: pulumi.Input; /** * ARN of an IAM role that allows the service to control your user’s access to your Amazon S3 bucket. */ role: pulumi.Input; /** * Server ID of the Transfer Server (e.g., `s-12345678`) */ serverId: pulumi.Input; /** * Map of tags to assign to the resource. If configured with a provider `defaultTags` configuration block present, tags with matching keys will overwrite those defined at the provider-level. */ tags?: pulumi.Input<{ [key: string]: pulumi.Input; } | undefined>; /** * Name used for log in to your SFTP server. */ userName: pulumi.Input; } //# sourceMappingURL=user.d.ts.map