permission_sets
Creates, updates, deletes or gets a permission_set
resource or lists permission_sets
in a region
Overview
Name | permission_sets |
Type | Resource |
Description | Resource Type definition for SSO PermissionSet |
Id | aws.sso.permission_sets |
Fields
Name | Datatype | Description |
---|---|---|
name | string | The name you want to assign to this permission set. |
permission_set_arn | string | The permission set that the policy will be attached to |
description | string | The permission set description. |
instance_arn | string | The sso instance arn that the permission set is owned. |
session_duration | string | The length of time that a user can be signed in to an AWS account. |
relay_state_type | string | The relay state URL that redirect links to any service in the AWS Management Console. |
managed_policies | array | |
inline_policy | object | The inline policy to put in permission set. |
tags | array | |
customer_managed_policy_references | array | |
permissions_boundary | object | |
region | string | AWS region. |
Methods
Name | Accessible by | Required Params |
---|---|---|
create_resource | INSERT | Name, InstanceArn, region |
delete_resource | DELETE | data__Identifier, region |
update_resource | UPDATE | data__Identifier, data__PatchDocument, region |
list_resources | SELECT | region |
get_resource | SELECT | data__Identifier, region |
SELECT
examples
Gets all permission_sets
in a region.
SELECT
region,
name,
permission_set_arn,
description,
instance_arn,
session_duration,
relay_state_type,
managed_policies,
inline_policy,
tags,
customer_managed_policy_references,
permissions_boundary
FROM aws.sso.permission_sets
WHERE region = 'us-east-1';
Gets all properties from an individual permission_set
.
SELECT
region,
name,
permission_set_arn,
description,
instance_arn,
session_duration,
relay_state_type,
managed_policies,
inline_policy,
tags,
customer_managed_policy_references,
permissions_boundary
FROM aws.sso.permission_sets
WHERE region = 'us-east-1' AND data__Identifier = '<InstanceArn>|<PermissionSetArn>';
INSERT
example
Use the following StackQL query and manifest file to create a new permission_set
resource, using stack-deploy
.
- Required Properties
- All Properties
- Manifest
/*+ create */
INSERT INTO aws.sso.permission_sets (
Name,
InstanceArn,
region
)
SELECT
'{{ Name }}',
'{{ InstanceArn }}',
'{{ region }}';
/*+ create */
INSERT INTO aws.sso.permission_sets (
Name,
Description,
InstanceArn,
SessionDuration,
RelayStateType,
ManagedPolicies,
InlinePolicy,
Tags,
CustomerManagedPolicyReferences,
PermissionsBoundary,
region
)
SELECT
'{{ Name }}',
'{{ Description }}',
'{{ InstanceArn }}',
'{{ SessionDuration }}',
'{{ RelayStateType }}',
'{{ ManagedPolicies }}',
'{{ InlinePolicy }}',
'{{ Tags }}',
'{{ CustomerManagedPolicyReferences }}',
'{{ PermissionsBoundary }}',
'{{ region }}';
version: 1
name: stack name
description: stack description
providers:
- aws
globals:
- name: region
value: '{{ vars.AWS_REGION }}'
resources:
- name: permission_set
props:
- name: Name
value: '{{ Name }}'
- name: Description
value: '{{ Description }}'
- name: InstanceArn
value: '{{ InstanceArn }}'
- name: SessionDuration
value: '{{ SessionDuration }}'
- name: RelayStateType
value: '{{ RelayStateType }}'
- name: ManagedPolicies
value:
- '{{ ManagedPolicies[0] }}'
- name: InlinePolicy
value: {}
- name: Tags
value:
- Key: '{{ Key }}'
Value: '{{ Value }}'
- name: CustomerManagedPolicyReferences
value:
- Name: '{{ Name }}'
Path: '{{ Path }}'
- name: PermissionsBoundary
value:
CustomerManagedPolicyReference: null
ManagedPolicyArn: null
DELETE
example
/*+ delete */
DELETE FROM aws.sso.permission_sets
WHERE data__Identifier = '<InstanceArn|PermissionSetArn>'
AND region = 'us-east-1';
Permissions
To operate on the permission_sets
resource, the following permissions are required:
Create
sso:CreatePermissionSet,
sso:PutInlinePolicyToPermissionSet,
sso:AttachManagedPolicyToPermissionSet,
sso:AttachCustomerManagedPolicyReferenceToPermissionSet,
sso:PutPermissionsBoundaryToPermissionSet,
sso:TagResource,
sso:DescribePermissionSet,
sso:ListTagsForResource,
sso:ListManagedPoliciesInPermissionSet,
sso:ListCustomerManagedPolicyReferencesInPermissionSet,
sso:GetInlinePolicyForPermissionSet,
sso:GetPermissionsBoundaryForPermissionSet
Read
sso:DescribePermissionSet,
sso:ListTagsForResource,
sso:ListManagedPoliciesInPermissionSet,
sso:ListCustomerManagedPolicyReferencesInPermissionSet,
sso:GetInlinePolicyForPermissionSet,
sso:GetPermissionsBoundaryForPermissionSet
Update
sso:UpdatePermissionSet,
sso:TagResource,
sso:UntagResource,
sso:ListTagsForResource,
sso:AttachManagedPolicyToPermissionSet,
sso:AttachCustomerManagedPolicyReferenceToPermissionSet,
sso:DetachManagedPolicyFromPermissionSet,
sso:DetachCustomerManagedPolicyReferenceFromPermissionSet,
sso:ListManagedPoliciesInPermissionSet,
sso:ListCustomerManagedPolicyReferencesInPermissionSet,
sso:PutInlinePolicyToPermissionSet,
sso:GetPermissionsBoundaryForPermissionSet,
sso:DeletePermissionsBoundaryFromPermissionSet,
sso:PutPermissionsBoundaryToPermissionSet,
sso:DeleteInlinePolicyFromPermissionSet,
sso:ProvisionPermissionSet,
sso:DescribePermissionSet,
sso:GetInlinePolicyForPermissionSet,
sso:DescribePermissionSetProvisioningStatus
Delete
sso:DeletePermissionSet
List
sso:DescribePermissionSet