Skip to main content

instance_access_control_attribute_configurations

Creates, updates, deletes or gets an instance_access_control_attribute_configuration resource or lists instance_access_control_attribute_configurations in a region

Overview

Nameinstance_access_control_attribute_configurations
TypeResource
DescriptionResource Type definition for SSO InstanceAccessControlAttributeConfiguration
Idaws.sso.instance_access_control_attribute_configurations

Fields

NameDatatypeDescription
instance_arnstringThe ARN of the AWS SSO instance under which the operation will be executed.
instance_access_control_attribute_configurationobjectThe InstanceAccessControlAttributeConfiguration property has been deprecated but is still supported for backwards compatibility purposes. We recomend that you use AccessControlAttributes property instead.
access_control_attributesarray
regionstringAWS region.

Methods

NameAccessible byRequired Params
create_resourceINSERTInstanceArn, region
delete_resourceDELETEdata__Identifier, region
update_resourceUPDATEdata__Identifier, data__PatchDocument, region
list_resourcesSELECTregion
get_resourceSELECTdata__Identifier, region

SELECT examples

Gets all instance_access_control_attribute_configurations in a region.

SELECT
region,
instance_arn,
instance_access_control_attribute_configuration,
access_control_attributes
FROM aws.sso.instance_access_control_attribute_configurations
WHERE region = 'us-east-1';

Gets all properties from an individual instance_access_control_attribute_configuration.

SELECT
region,
instance_arn,
instance_access_control_attribute_configuration,
access_control_attributes
FROM aws.sso.instance_access_control_attribute_configurations
WHERE region = 'us-east-1' AND data__Identifier = '<InstanceArn>';

INSERT example

Use the following StackQL query and manifest file to create a new instance_access_control_attribute_configuration resource, using stack-deploy.

/*+ create */
INSERT INTO aws.sso.instance_access_control_attribute_configurations (
InstanceArn,
region
)
SELECT
'{{ InstanceArn }}',
'{{ region }}';

DELETE example

/*+ delete */
DELETE FROM aws.sso.instance_access_control_attribute_configurations
WHERE data__Identifier = '<InstanceArn>'
AND region = 'us-east-1';

Permissions

To operate on the instance_access_control_attribute_configurations resource, the following permissions are required:

Create

sso:CreateInstanceAccessControlAttributeConfiguration,
sso:UpdateApplicationProfileForAWSAccountInstance,
sso:DescribeInstanceAccessControlAttributeConfiguration

Read

sso:DescribeInstanceAccessControlAttributeConfiguration

Update

sso:UpdateInstanceAccessControlAttributeConfiguration,
sso:DescribeInstanceAccessControlAttributeConfiguration

Delete

sso:DeleteInstanceAccessControlAttributeConfiguration,
sso:DescribeInstanceAccessControlAttributeConfiguration

List

sso:DescribeInstanceAccessControlAttributeConfiguration