Interface CfnPermissionSet.PermissionsBoundaryProperty
- All Superinterfaces:
software.amazon.jsii.JsiiSerializable
- All Known Implementing Classes:
CfnPermissionSet.PermissionsBoundaryProperty.Jsii$Proxy
- Enclosing class:
CfnPermissionSet
Specify either CustomerManagedPolicyReference to use the name and path of a customer managed policy, or ManagedPolicyArn to use the ARN of an AWS managed policy. A permissions boundary represents the maximum permissions that any policy can grant your role. For more information, see Permissions boundaries for IAM entities in the IAM User Guide .
Policies used as permissions boundaries don't provide permissions. You must also attach an IAM policy to the role. To learn how the effective permissions for a role are evaluated, see IAM JSON policy evaluation logic in the IAM User Guide .
Example:
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import software.amazon.awscdk.services.sso.*;
PermissionsBoundaryProperty permissionsBoundaryProperty = PermissionsBoundaryProperty.builder()
.customerManagedPolicyReference(CustomerManagedPolicyReferenceProperty.builder()
.name("name")
// the properties below are optional
.path("path")
.build())
.managedPolicyArn("managedPolicyArn")
.build();
- See Also:
-
Nested Class Summary
Nested ClassesModifier and TypeInterfaceDescriptionstatic final classA builder forCfnPermissionSet.PermissionsBoundaryPropertystatic final classAn implementation forCfnPermissionSet.PermissionsBoundaryProperty -
Method Summary
Methods inherited from interface software.amazon.jsii.JsiiSerializable
$jsii$toJson
-
Method Details
-
getCustomerManagedPolicyReference
Specifies the name and path of a customer managed policy.You must have an IAM policy that matches the name and path in each AWS account where you want to deploy your permission set.
Returns union: either
IResolvableorCfnPermissionSet.CustomerManagedPolicyReferenceProperty- See Also:
-
getManagedPolicyArn
The AWS managed policy ARN that you want to attach to a permission set as a permissions boundary.- See Also:
-
builder
-