import * as pulumi from "@pulumi/pulumi"; import * as inputs from "../types/input"; import * as outputs from "../types/output"; /** * PolicyOrchestrator helps managing project+zone level policy resources (e.g. * OS Policy Assignments), by providing tools to create, update and delete them * across projects and locations, at scale. * * ## Example Usage * * ### Osconfigv2 Policy Orchestrator For Organization Basic * * ```typescript * import * as pulumi from "@pulumi/pulumi"; * import * as gcp from "@pulumi/gcp"; * * const policyOrchestratorForOrganization = new gcp.osconfig.V2PolicyOrchestratorForOrganization("policy_orchestrator_for_organization", { * policyOrchestratorId: "po-org", * organizationId: "123456789", * state: "ACTIVE", * action: "UPSERT", * orchestratedResource: { * id: "test-orchestrated-resource-org", * osPolicyAssignmentV1Payload: { * osPolicies: [{ * id: "test-os-policy-org", * mode: "VALIDATION", * resourceGroups: [{ * resources: [{ * id: "resource-tf", * file: { * content: "file-content-tf", * path: "file-path-tf-1", * state: "PRESENT", * }, * }], * }], * }], * instanceFilter: { * inventories: [{ * osShortName: "windows-10", * }], * }, * rollout: { * disruptionBudget: { * percent: 100, * }, * minWaitDuration: "60s", * }, * }, * }, * labels: { * state: "active", * }, * orchestrationScope: { * selectors: [{ * locationSelector: { * includedLocations: [""], * }, * }], * }, * }); * ``` * * ## Import * * PolicyOrchestratorForOrganization can be imported using any of these accepted formats: * * * `organizations/{{organization_id}}/locations/global/policyOrchestrators/{{policy_orchestrator_id}}` * * `{{organization_id}}/{{policy_orchestrator_id}}` * * When using the `pulumi import` command, PolicyOrchestratorForOrganization can be imported using one of the formats above. For example: * * ```sh * $ pulumi import gcp:osconfig/v2PolicyOrchestratorForOrganization:V2PolicyOrchestratorForOrganization default organizations/{{organization_id}}/locations/global/policyOrchestrators/{{policy_orchestrator_id}} * $ pulumi import gcp:osconfig/v2PolicyOrchestratorForOrganization:V2PolicyOrchestratorForOrganization default {{organization_id}}/{{policy_orchestrator_id}} * ``` */ export declare class V2PolicyOrchestratorForOrganization extends pulumi.CustomResource { /** * Get an existing V2PolicyOrchestratorForOrganization resource's state with the given name, ID, and optional extra * properties used to qualify the lookup. * * @param name The _unique_ name of the resulting resource. * @param id The _unique_ provider ID of the resource to lookup. * @param state Any extra arguments used during the lookup. * @param opts Optional settings to control the behavior of the CustomResource. */ static get(name: string, id: pulumi.Input, state?: V2PolicyOrchestratorForOrganizationState, opts?: pulumi.CustomResourceOptions): V2PolicyOrchestratorForOrganization; /** * Returns true if the given object is an instance of V2PolicyOrchestratorForOrganization. This is designed to work even * when multiple copies of the Pulumi SDK have been loaded into the same process. */ static isInstance(obj: any): obj is V2PolicyOrchestratorForOrganization; /** * Required. Action to be done by the orchestrator in * `projects/{project_id}/zones/{zone_id}` locations defined by the * `orchestrationScope`. Allowed values: * - `UPSERT` - Orchestrator will create or update target resources. * - `DELETE` - Orchestrator will delete target resources, if they exist */ readonly action: pulumi.Output; /** * Output only. Timestamp when the policy orchestrator resource was created. */ readonly createTime: pulumi.Output; /** * Optional. Freeform text describing the purpose of the resource. */ readonly description: pulumi.Output; /** * All of labels (key/value pairs) present on the resource in GCP, including the labels configured through Pulumi, other clients and services. */ readonly effectiveLabels: pulumi.Output<{ [key: string]: string; }>; /** * Output only. This checksum is computed by the server based on the value of other * fields, and may be sent on update and delete requests to ensure the * client has an up-to-date value before proceeding. */ readonly etag: pulumi.Output; /** * Optional. Labels as key value pairs * **Note**: This field is non-authoritative, and will only manage the labels present in your configuration. * Please refer to the field `effectiveLabels` for all of the labels present on the resource. */ readonly labels: pulumi.Output<{ [key: string]: string; } | undefined>; /** * Immutable. Identifier. In form of * * `organizations/{organization_id}/locations/global/policyOrchestrators/{orchestrator_id}` * * `folders/{folder_id}/locations/global/policyOrchestrators/{orchestrator_id}` * * `projects/{project_id_or_number}/locations/global/policyOrchestrators/{orchestrator_id}` */ readonly name: pulumi.Output; /** * Represents a resource that is being orchestrated by the policy orchestrator. * Structure is documented below. */ readonly orchestratedResource: pulumi.Output; /** * Defines a set of selectors which drive which resources are in scope of policy * orchestration. * Structure is documented below. */ readonly orchestrationScope: pulumi.Output; /** * Describes the state of the orchestration process. * Structure is documented below. */ readonly orchestrationStates: pulumi.Output; /** * Part of `parent`. Required. The parent resource name in the form of: * * `organizations/{organization_id}/locations/global` * * `folders/{folder_id}/locations/global` * * `projects/{project_id_or_number}/locations/global` */ readonly organizationId: pulumi.Output; /** * Required. The logical identifier of the policy orchestrator, with the following * restrictions: * * Must contain only lowercase letters, numbers, and hyphens. * * Must start with a letter. * * Must be between 1-63 characters. * * Must end with a number or a letter. * * Must be unique within the parent. */ readonly policyOrchestratorId: pulumi.Output; /** * The combination of labels configured directly on the resource * and default labels configured on the provider. */ readonly pulumiLabels: pulumi.Output<{ [key: string]: string; }>; /** * Output only. Set to true, if the there are ongoing changes being applied by the * orchestrator. */ readonly reconciling: pulumi.Output; /** * Optional. State of the orchestrator. Can be updated to change orchestrator behaviour. * Allowed values: * - `ACTIVE` - orchestrator is actively looking for actions to be taken. * - `STOPPED` - orchestrator won't make any changes. * Note: There might be more states added in the future. We use string here * instead of an enum, to avoid the need of propagating new states to all the * client code. */ readonly state: pulumi.Output; /** * Output only. Timestamp when the policy orchestrator resource was last modified. */ readonly updateTime: pulumi.Output; /** * Create a V2PolicyOrchestratorForOrganization resource with the given unique name, arguments, and options. * * @param name The _unique_ name of the resource. * @param args The arguments to use to populate this resource's properties. * @param opts A bag of options that control this resource's behavior. */ constructor(name: string, args: V2PolicyOrchestratorForOrganizationArgs, opts?: pulumi.CustomResourceOptions); } /** * Input properties used for looking up and filtering V2PolicyOrchestratorForOrganization resources. */ export interface V2PolicyOrchestratorForOrganizationState { /** * Required. Action to be done by the orchestrator in * `projects/{project_id}/zones/{zone_id}` locations defined by the * `orchestrationScope`. Allowed values: * - `UPSERT` - Orchestrator will create or update target resources. * - `DELETE` - Orchestrator will delete target resources, if they exist */ action?: pulumi.Input; /** * Output only. Timestamp when the policy orchestrator resource was created. */ createTime?: pulumi.Input; /** * Optional. Freeform text describing the purpose of the resource. */ description?: pulumi.Input; /** * All of labels (key/value pairs) present on the resource in GCP, including the labels configured through Pulumi, other clients and services. */ effectiveLabels?: pulumi.Input<{ [key: string]: pulumi.Input; }>; /** * Output only. This checksum is computed by the server based on the value of other * fields, and may be sent on update and delete requests to ensure the * client has an up-to-date value before proceeding. */ etag?: pulumi.Input; /** * Optional. Labels as key value pairs * **Note**: This field is non-authoritative, and will only manage the labels present in your configuration. * Please refer to the field `effectiveLabels` for all of the labels present on the resource. */ labels?: pulumi.Input<{ [key: string]: pulumi.Input; }>; /** * Immutable. Identifier. In form of * * `organizations/{organization_id}/locations/global/policyOrchestrators/{orchestrator_id}` * * `folders/{folder_id}/locations/global/policyOrchestrators/{orchestrator_id}` * * `projects/{project_id_or_number}/locations/global/policyOrchestrators/{orchestrator_id}` */ name?: pulumi.Input; /** * Represents a resource that is being orchestrated by the policy orchestrator. * Structure is documented below. */ orchestratedResource?: pulumi.Input; /** * Defines a set of selectors which drive which resources are in scope of policy * orchestration. * Structure is documented below. */ orchestrationScope?: pulumi.Input; /** * Describes the state of the orchestration process. * Structure is documented below. */ orchestrationStates?: pulumi.Input[]>; /** * Part of `parent`. Required. The parent resource name in the form of: * * `organizations/{organization_id}/locations/global` * * `folders/{folder_id}/locations/global` * * `projects/{project_id_or_number}/locations/global` */ organizationId?: pulumi.Input; /** * Required. The logical identifier of the policy orchestrator, with the following * restrictions: * * Must contain only lowercase letters, numbers, and hyphens. * * Must start with a letter. * * Must be between 1-63 characters. * * Must end with a number or a letter. * * Must be unique within the parent. */ policyOrchestratorId?: pulumi.Input; /** * The combination of labels configured directly on the resource * and default labels configured on the provider. */ pulumiLabels?: pulumi.Input<{ [key: string]: pulumi.Input; }>; /** * Output only. Set to true, if the there are ongoing changes being applied by the * orchestrator. */ reconciling?: pulumi.Input; /** * Optional. State of the orchestrator. Can be updated to change orchestrator behaviour. * Allowed values: * - `ACTIVE` - orchestrator is actively looking for actions to be taken. * - `STOPPED` - orchestrator won't make any changes. * Note: There might be more states added in the future. We use string here * instead of an enum, to avoid the need of propagating new states to all the * client code. */ state?: pulumi.Input; /** * Output only. Timestamp when the policy orchestrator resource was last modified. */ updateTime?: pulumi.Input; } /** * The set of arguments for constructing a V2PolicyOrchestratorForOrganization resource. */ export interface V2PolicyOrchestratorForOrganizationArgs { /** * Required. Action to be done by the orchestrator in * `projects/{project_id}/zones/{zone_id}` locations defined by the * `orchestrationScope`. Allowed values: * - `UPSERT` - Orchestrator will create or update target resources. * - `DELETE` - Orchestrator will delete target resources, if they exist */ action: pulumi.Input; /** * Optional. Freeform text describing the purpose of the resource. */ description?: pulumi.Input; /** * Optional. Labels as key value pairs * **Note**: This field is non-authoritative, and will only manage the labels present in your configuration. * Please refer to the field `effectiveLabels` for all of the labels present on the resource. */ labels?: pulumi.Input<{ [key: string]: pulumi.Input; }>; /** * Represents a resource that is being orchestrated by the policy orchestrator. * Structure is documented below. */ orchestratedResource: pulumi.Input; /** * Defines a set of selectors which drive which resources are in scope of policy * orchestration. * Structure is documented below. */ orchestrationScope?: pulumi.Input; /** * Part of `parent`. Required. The parent resource name in the form of: * * `organizations/{organization_id}/locations/global` * * `folders/{folder_id}/locations/global` * * `projects/{project_id_or_number}/locations/global` */ organizationId: pulumi.Input; /** * Required. The logical identifier of the policy orchestrator, with the following * restrictions: * * Must contain only lowercase letters, numbers, and hyphens. * * Must start with a letter. * * Must be between 1-63 characters. * * Must end with a number or a letter. * * Must be unique within the parent. */ policyOrchestratorId: pulumi.Input; /** * Optional. State of the orchestrator. Can be updated to change orchestrator behaviour. * Allowed values: * - `ACTIVE` - orchestrator is actively looking for actions to be taken. * - `STOPPED` - orchestrator won't make any changes. * Note: There might be more states added in the future. We use string here * instead of an enum, to avoid the need of propagating new states to all the * client code. */ state?: pulumi.Input; }