Skip to main content

vpc_block_public_access_exclusions

Creates, updates, deletes or gets a vpc_block_public_access_exclusion resource or lists vpc_block_public_access_exclusions in a region

Overview

Namevpc_block_public_access_exclusions
TypeResource
DescriptionResource Type definition for AWS::EC2::VPCBlockPublicAccessExclusion.
Idawscc.ec2.vpc_block_public_access_exclusions

Fields

NameDatatypeDescription
exclusion_idstringThe ID of the exclusion
internet_gateway_exclusion_modestringThe desired Block Public Access Exclusion Mode for a specific VPC/Subnet.
vpc_idstringThe ID of the vpc. Required only if you don't specify SubnetId.
subnet_idstringThe ID of the subnet. Required only if you don't specify VpcId
tagsarrayAn array of key-value pairs to apply to this resource.
regionstringAWS region.

For more information, see AWS::EC2::VPCBlockPublicAccessExclusion.

Methods

NameResourceAccessible byRequired Params
create_resourcevpc_block_public_access_exclusionsINSERTInternetGatewayExclusionMode, region
delete_resourcevpc_block_public_access_exclusionsDELETEIdentifier, region
update_resourcevpc_block_public_access_exclusionsUPDATEIdentifier, PatchDocument, region
list_resourcesvpc_block_public_access_exclusions_list_onlySELECTregion
get_resourcevpc_block_public_access_exclusionsSELECTIdentifier, region

SELECT examples

Gets all properties from an individual vpc_block_public_access_exclusion.

SELECT
region,
exclusion_id,
internet_gateway_exclusion_mode,
vpc_id,
subnet_id,
tags
FROM awscc.ec2.vpc_block_public_access_exclusions
WHERE
region = 'us-east-1' AND
Identifier = '{{ exclusion_id }}';

INSERT example

Use the following StackQL query and manifest file to create a new vpc_block_public_access_exclusion resource, using stack-deploy.

/*+ create */
INSERT INTO awscc.ec2.vpc_block_public_access_exclusions (
InternetGatewayExclusionMode,
region
)
SELECT
'{{ internet_gateway_exclusion_mode }}',
'{{ region }}';

UPDATE example

Use the following StackQL query and manifest file to update a vpc_block_public_access_exclusion resource, using stack-deploy.

/*+ update */
UPDATE awscc.ec2.vpc_block_public_access_exclusions
SET PatchDocument = string('{{ {
"InternetGatewayExclusionMode": internet_gateway_exclusion_mode,
"Tags": tags
} | generate_patch_document }}')
WHERE
region = '{{ region }}' AND
Identifier = '{{ exclusion_id }}';

DELETE example

/*+ delete */
DELETE FROM awscc.ec2.vpc_block_public_access_exclusions
WHERE
Identifier = '{{ exclusion_id }}' AND
region = 'us-east-1';

Permissions

To operate on the vpc_block_public_access_exclusions resource, the following permissions are required:

ec2:DescribeVpcBlockPublicAccessExclusions,
ec2:CreateVpcBlockPublicAccessExclusion,
ec2:CreateTags