Skip to main content

instance_access_control_attribute_configurations

Creates, updates, deletes or gets an instance_access_control_attribute_configuration resource or lists instance_access_control_attribute_configurations in a region

Overview

Nameinstance_access_control_attribute_configurations
TypeResource
DescriptionResource Type definition for SSO InstanceAccessControlAttributeConfiguration
Idawscc.sso.instance_access_control_attribute_configurations

Fields

NameDatatypeDescription
instance_arnstringThe ARN of the AWS SSO instance under which the operation will be executed.
instance_access_control_attribute_configurationobjectThe InstanceAccessControlAttributeConfiguration property has been deprecated but is still supported for backwards compatibility purposes. We recomend that you use AccessControlAttributes property instead.
access_control_attributesarray
regionstringAWS region.

For more information, see AWS::SSO::InstanceAccessControlAttributeConfiguration.

Methods

NameResourceAccessible byRequired Params
create_resourceinstance_access_control_attribute_configurationsINSERTInstanceArn, region
delete_resourceinstance_access_control_attribute_configurationsDELETEIdentifier, region
update_resourceinstance_access_control_attribute_configurationsUPDATEIdentifier, PatchDocument, region
list_resourcesinstance_access_control_attribute_configurations_list_onlySELECTregion
get_resourceinstance_access_control_attribute_configurationsSELECTIdentifier, region

SELECT examples

Gets all properties from an individual instance_access_control_attribute_configuration.

SELECT
region,
instance_arn,
instance_access_control_attribute_configuration,
access_control_attributes
FROM awscc.sso.instance_access_control_attribute_configurations
WHERE
region = 'us-east-1' AND
Identifier = '{{ instance_arn }}';

INSERT example

Use the following StackQL query and manifest file to create a new instance_access_control_attribute_configuration resource, using stack-deploy.

/*+ create */
INSERT INTO awscc.sso.instance_access_control_attribute_configurations (
InstanceArn,
region
)
SELECT
'{{ instance_arn }}',
'{{ region }}';

UPDATE example

Use the following StackQL query and manifest file to update a instance_access_control_attribute_configuration resource, using stack-deploy.

/*+ update */
UPDATE awscc.sso.instance_access_control_attribute_configurations
SET PatchDocument = string('{{ {
"InstanceAccessControlAttributeConfiguration": instance_access_control_attribute_configuration,
"AccessControlAttributes": access_control_attributes
} | generate_patch_document }}')
WHERE
region = '{{ region }}' AND
Identifier = '{{ instance_arn }}';

DELETE example

/*+ delete */
DELETE FROM awscc.sso.instance_access_control_attribute_configurations
WHERE
Identifier = '{{ instance_arn }}' AND
region = 'us-east-1';

Permissions

To operate on the instance_access_control_attribute_configurations resource, the following permissions are required:

sso:CreateInstanceAccessControlAttributeConfiguration,
sso:UpdateApplicationProfileForAWSAccountInstance,
sso:DescribeInstanceAccessControlAttributeConfiguration