permissions
Creates, updates, deletes or gets a permission
resource or lists permissions
in a region
Overview
Name | permissions |
Type | Resource |
Description | Definition of AWS::QBusiness::Permission Resource Type |
Id | aws.qbusiness.permissions |
Fields
Name | Datatype | Description |
---|---|---|
application_id | string | |
statement_id | string | |
actions | array | |
principal | string | |
region | string | AWS region. |
For more information, see AWS::QBusiness::Permission
.
Methods
Name | Accessible by | Required Params |
---|---|---|
create_resource | INSERT | ApplicationId, StatementId, Actions, Principal, region |
delete_resource | DELETE | data__Identifier, region |
list_resources | SELECT | region |
get_resource | SELECT | data__Identifier, region |
SELECT
examples
Gets all permissions
in a region.
SELECT
region,
application_id,
statement_id,
actions,
principal
FROM aws.qbusiness.permissions
WHERE region = 'us-east-1';
Gets all properties from an individual permission
.
SELECT
region,
application_id,
statement_id,
actions,
principal
FROM aws.qbusiness.permissions
WHERE region = 'us-east-1' AND data__Identifier = '<ApplicationId>|<StatementId>';
INSERT
example
Use the following StackQL query and manifest file to create a new permission
resource, using stack-deploy
.
- Required Properties
- All Properties
- Manifest
/*+ create */
INSERT INTO aws.qbusiness.permissions (
ApplicationId,
StatementId,
Actions,
Principal,
region
)
SELECT
'{{ ApplicationId }}',
'{{ StatementId }}',
'{{ Actions }}',
'{{ Principal }}',
'{{ region }}';
/*+ create */
INSERT INTO aws.qbusiness.permissions (
ApplicationId,
StatementId,
Actions,
Principal,
region
)
SELECT
'{{ ApplicationId }}',
'{{ StatementId }}',
'{{ Actions }}',
'{{ Principal }}',
'{{ region }}';
version: 1
name: stack name
description: stack description
providers:
- aws
globals:
- name: region
value: '{{ vars.AWS_REGION }}'
resources:
- name: permission
props:
- name: ApplicationId
value: '{{ ApplicationId }}'
- name: StatementId
value: '{{ StatementId }}'
- name: Actions
value:
- '{{ Actions[0] }}'
- name: Principal
value: '{{ Principal }}'
DELETE
example
/*+ delete */
DELETE FROM aws.qbusiness.permissions
WHERE data__Identifier = '<ApplicationId|StatementId>'
AND region = 'us-east-1';
Permissions
To operate on the permissions
resource, the following permissions are required:
Create
qbusiness:AssociatePermission,
qbusiness:PutResourcePolicy
Read
qbusiness:GetPolicy
Delete
qbusiness:DisassociatePermission,
qbusiness:PutResourcePolicy
List
qbusiness:GetPolicy