View a markdown version of this page

Use PutResourcePolicy with an AWS SDK - AWS SDK Code Examples

There are more AWS SDK examples available in the AWS Doc SDK Examples GitHub repo.

Use PutResourcePolicy with an AWS SDK

The following code example shows how to use PutResourcePolicy.

Action examples are code excerpts from larger programs and must be run in context. You can see this action in context in the following code example:

Python
SDK for Python (Boto3)
Note

There's more on GitHub. Find the complete example and learn how to set up and run in the AWS Code Examples Repository.

def put_resource_policy( self, log_group_arn: str, vpc_endpoint_id: str, ) -> dict[str, Any]: """ Creates or updates a resource-scoped policy on a log group that grants the syslog.logs.amazonaws.com service principal permission to call logs:PutLogEvents and logs:CreateLogStream. A resource-scoped policy (one attached to a specific log group) is specified with resourceArn and policyDocument. The PutResourcePolicy API does not allow policyName to be combined with resourceArn. :param log_group_arn: The ARN of the log group (with trailing :*). :param vpc_endpoint_id: The VPC endpoint ID to scope the condition. :return: The resource policy response. """ policy_document = json.dumps( { "Version":"2012-10-17", "Statement": [ { "Sid": "SyslogIngestPermissions", "Effect": "Allow", "Principal": {"Service": "syslog.logs.amazonaws.com"}, "Action": [ "logs:PutLogEvents", "logs:CreateLogStream", ], "Resource": log_group_arn, "Condition": { "StringEquals": {"aws:sourceVpce": vpc_endpoint_id} }, } ], } ) try: response = self.logs_client.put_resource_policy( policyDocument=policy_document, resourceArn=log_group_arn, ) logger.info("Put resource policy on log group '%s'.", log_group_arn) return response except ClientError as error: logger.error( "Failed to put resource policy: %s", error.response["Error"]["Message"], ) raise
  • For API details, see PutResourcePolicy in AWS SDK for Python (Boto3) API Reference.