CfnResourcePolicyProps
- class aws_cdk.aws_eventsv2.CfnResourcePolicyProps(*, event_bus_arn, policy_document)
Bases:
objectProperties for defining a
CfnResourcePolicy.- Parameters:
event_bus_arn (
str) – The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.policy_document (
Any) – The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see “Changes that I make are not always immediately visible” in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.
- See:
- ExampleMetadata:
fixture=_generated
Example:
# The code below shows an example of how to instantiate this type. # The values are placeholders you should change. from aws_cdk import aws_eventsv2 as eventsv2 # policy_document: Any cfn_resource_policy_props = eventsv2.CfnResourcePolicyProps( event_bus_arn="eventBusArn", policy_document=policy_document )
Attributes
- event_bus_arn
The Amazon Resource Name (ARN) of the event bus whose resource policy this is.
The bus must already exist. This resource does not create it.
- policy_document
The resource policy document, as a JSON object.
The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see “Changes that I make are not always immediately visible” in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.