@aws-cdk/aws-eks-v2-alpha
Version:
The CDK Construct Library for AWS::EKS
318 lines • 34.3 kB
JavaScript
;
var __runInitializers = (this && this.__runInitializers) || function (thisArg, initializers, value) {
var useValue = arguments.length > 2;
for (var i = 0; i < initializers.length; i++) {
value = useValue ? initializers[i].call(thisArg, value) : initializers[i].call(thisArg);
}
return useValue ? value : void 0;
};
var __esDecorate = (this && this.__esDecorate) || function (ctor, descriptorIn, decorators, contextIn, initializers, extraInitializers) {
function accept(f) { if (f !== void 0 && typeof f !== "function") throw new TypeError("Function expected"); return f; }
var kind = contextIn.kind, key = kind === "getter" ? "get" : kind === "setter" ? "set" : "value";
var target = !descriptorIn && ctor ? contextIn["static"] ? ctor : ctor.prototype : null;
var descriptor = descriptorIn || (target ? Object.getOwnPropertyDescriptor(target, contextIn.name) : {});
var _, done = false;
for (var i = decorators.length - 1; i >= 0; i--) {
var context = {};
for (var p in contextIn) context[p] = p === "access" ? {} : contextIn[p];
for (var p in contextIn.access) context.access[p] = contextIn.access[p];
context.addInitializer = function (f) { if (done) throw new TypeError("Cannot add initializers after decoration has completed"); extraInitializers.push(accept(f || null)); };
var result = (0, decorators[i])(kind === "accessor" ? { get: descriptor.get, set: descriptor.set } : descriptor[key], context);
if (kind === "accessor") {
if (result === void 0) continue;
if (result === null || typeof result !== "object") throw new TypeError("Object expected");
if (_ = accept(result.get)) descriptor.get = _;
if (_ = accept(result.set)) descriptor.set = _;
if (_ = accept(result.init)) initializers.unshift(_);
}
else if (_ = accept(result)) {
if (kind === "field") initializers.unshift(_);
else descriptor[key] = _;
}
}
if (target) Object.defineProperty(target, contextIn.name, descriptor);
done = true;
};
Object.defineProperty(exports, "__esModule", { value: true });
exports.AccessEntry = exports.AccessEntryType = exports.AccessPolicy = exports.AccessPolicyArn = exports.AccessScopeType = void 0;
const jsiiDeprecationWarnings = require("../.warnings.jsii.js");
const JSII_RTTI_SYMBOL_1 = Symbol.for("jsii.rtti");
const aws_eks_1 = require("aws-cdk-lib/aws-eks");
const core_1 = require("aws-cdk-lib/core");
const metadata_resource_1 = require("aws-cdk-lib/core/lib/metadata-resource");
const prop_injectable_1 = require("aws-cdk-lib/core/lib/prop-injectable");
/**
* Represents the scope type of an access policy.
*
* The scope type determines the level of access granted by the policy.
*
* @export
* @enum {string}
*/
var AccessScopeType;
(function (AccessScopeType) {
/**
* The policy applies to a specific namespace within the cluster.
*/
AccessScopeType["NAMESPACE"] = "namespace";
/**
* The policy applies to the entire cluster.
*/
AccessScopeType["CLUSTER"] = "cluster";
})(AccessScopeType || (exports.AccessScopeType = AccessScopeType = {}));
/**
* Represents an Amazon EKS Access Policy ARN.
*
* Amazon EKS Access Policies are used to control access to Amazon EKS clusters.
*
* @see https://docs.aws.amazon.com/eks/latest/userguide/access-policies.html
*/
class AccessPolicyArn {
policyName;
static [JSII_RTTI_SYMBOL_1] = { fqn: "@aws-cdk/aws-eks-v2-alpha.AccessPolicyArn", version: "2.223.0-alpha.0" };
/**
* The Amazon EKS Admin Policy. This access policy includes permissions that grant an IAM principal
* most permissions to resources. When associated to an access entry, its access scope is typically
* one or more Kubernetes namespaces.
*/
static AMAZON_EKS_ADMIN_POLICY = AccessPolicyArn.of('AmazonEKSAdminPolicy');
/**
* The Amazon EKS Cluster Admin Policy. This access policy includes permissions that grant an IAM
* principal administrator access to a cluster. When associated to an access entry, its access scope
* is typically the cluster, rather than a Kubernetes namespace.
*/
static AMAZON_EKS_CLUSTER_ADMIN_POLICY = AccessPolicyArn.of('AmazonEKSClusterAdminPolicy');
/**
* The Amazon EKS Admin View Policy. This access policy includes permissions that grant an IAM principal
* access to list/view all resources in a cluster.
*/
static AMAZON_EKS_ADMIN_VIEW_POLICY = AccessPolicyArn.of('AmazonEKSAdminViewPolicy');
/**
* The Amazon EKS Edit Policy. This access policy includes permissions that allow an IAM principal
* to edit most Kubernetes resources.
*/
static AMAZON_EKS_EDIT_POLICY = AccessPolicyArn.of('AmazonEKSEditPolicy');
/**
* The Amazon EKS View Policy. This access policy includes permissions that grant an IAM principal
* access to list/view all resources in a cluster.
*/
static AMAZON_EKS_VIEW_POLICY = AccessPolicyArn.of('AmazonEKSViewPolicy');
/**
* Creates a new instance of the AccessPolicy class with the specified policy name.
* @param policyName The name of the access policy.
* @returns A new instance of the AccessPolicy class.
*/
static of(policyName) { return new AccessPolicyArn(policyName); }
/**
* The Amazon Resource Name (ARN) of the access policy.
*/
policyArn;
/**
* Constructs a new instance of the `AccessEntry` class.
*
* @param policyName - The name of the Amazon EKS access policy. This is used to construct the policy ARN.
*/
constructor(policyName) {
this.policyName = policyName;
this.policyArn = `arn:${core_1.Aws.PARTITION}:eks::aws:cluster-access-policy/${policyName}`;
}
}
exports.AccessPolicyArn = AccessPolicyArn;
/**
* Represents an Amazon EKS Access Policy that implements the IAccessPolicy interface.
*
* @implements {IAccessPolicy}
*/
class AccessPolicy {
static [JSII_RTTI_SYMBOL_1] = { fqn: "@aws-cdk/aws-eks-v2-alpha.AccessPolicy", version: "2.223.0-alpha.0" };
/**
* Import AccessPolicy by name.
*/
static fromAccessPolicyName(policyName, options) {
try {
jsiiDeprecationWarnings._aws_cdk_aws_eks_v2_alpha_AccessPolicyNameOptions(options);
}
catch (error) {
if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
Error.captureStackTrace(error, this.fromAccessPolicyName);
}
throw error;
}
class Import {
policy = `arn:${core_1.Aws.PARTITION}:eks::aws:cluster-access-policy/${policyName}`;
accessScope = {
type: options.accessScopeType,
namespaces: options.namespaces,
};
}
return new Import();
}
/**
* The scope of the access policy, which determines the level of access granted.
*/
accessScope;
/**
* The access policy itself, which defines the specific permissions.
*/
policy;
/**
* Constructs a new instance of the AccessPolicy class.
*
* @param {AccessPolicyProps} props - The properties for configuring the access policy.
*/
constructor(props) {
try {
jsiiDeprecationWarnings._aws_cdk_aws_eks_v2_alpha_AccessPolicyProps(props);
}
catch (error) {
if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
Error.captureStackTrace(error, AccessPolicy);
}
throw error;
}
this.accessScope = props.accessScope;
this.policy = props.policy.policyArn;
}
}
exports.AccessPolicy = AccessPolicy;
/**
* Represents the different types of access entries that can be used in an Amazon EKS cluster.
*
* @enum {string}
*/
var AccessEntryType;
(function (AccessEntryType) {
/**
* Represents a standard access entry.
*/
AccessEntryType["STANDARD"] = "STANDARD";
/**
* Represents a Fargate Linux access entry.
*/
AccessEntryType["FARGATE_LINUX"] = "FARGATE_LINUX";
/**
* Represents an EC2 Linux access entry.
*/
AccessEntryType["EC2_LINUX"] = "EC2_LINUX";
/**
* Represents an EC2 Windows access entry.
*/
AccessEntryType["EC2_WINDOWS"] = "EC2_WINDOWS";
})(AccessEntryType || (exports.AccessEntryType = AccessEntryType = {}));
/**
* Represents an access entry in an Amazon EKS cluster.
*
* An access entry defines the permissions and scope for a user or role to access an Amazon EKS cluster.
*
* @implements {IAccessEntry}
* @resource AWS::EKS::AccessEntry
*/
let AccessEntry = (() => {
let _classDecorators = [prop_injectable_1.propertyInjectable];
let _classDescriptor;
let _classExtraInitializers = [];
let _classThis;
let _classSuper = core_1.Resource;
let _instanceExtraInitializers = [];
let _addAccessPolicies_decorators;
var AccessEntry = class extends _classSuper {
static { _classThis = this; }
static {
const _metadata = typeof Symbol === "function" && Symbol.metadata ? Object.create(_classSuper[Symbol.metadata] ?? null) : void 0;
_addAccessPolicies_decorators = [(0, metadata_resource_1.MethodMetadata)()];
__esDecorate(this, null, _addAccessPolicies_decorators, { kind: "method", name: "addAccessPolicies", static: false, private: false, access: { has: obj => "addAccessPolicies" in obj, get: obj => obj.addAccessPolicies }, metadata: _metadata }, null, _instanceExtraInitializers);
__esDecorate(null, _classDescriptor = { value: _classThis }, _classDecorators, { kind: "class", name: _classThis.name, metadata: _metadata }, null, _classExtraInitializers);
AccessEntry = _classThis = _classDescriptor.value;
if (_metadata) Object.defineProperty(_classThis, Symbol.metadata, { enumerable: true, configurable: true, writable: true, value: _metadata });
}
static [JSII_RTTI_SYMBOL_1] = { fqn: "@aws-cdk/aws-eks-v2-alpha.AccessEntry", version: "2.223.0-alpha.0" };
/** Uniquely identifies this class. */
static PROPERTY_INJECTION_ID = '@aws-cdk.aws-eks-v2-alpha.AccessEntry';
/**
* Imports an `AccessEntry` from its attributes.
*
* @param scope - The parent construct.
* @param id - The ID of the imported construct.
* @param attrs - The attributes of the access entry to import.
* @returns The imported access entry.
*/
static fromAccessEntryAttributes(scope, id, attrs) {
try {
jsiiDeprecationWarnings._aws_cdk_aws_eks_v2_alpha_AccessEntryAttributes(attrs);
}
catch (error) {
if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
Error.captureStackTrace(error, this.fromAccessEntryAttributes);
}
throw error;
}
class Import extends core_1.Resource {
accessEntryName = attrs.accessEntryName;
accessEntryArn = attrs.accessEntryArn;
}
return new Import(scope, id);
}
/**
* The name of the access entry.
*/
accessEntryName = __runInitializers(this, _instanceExtraInitializers);
/**
* The Amazon Resource Name (ARN) of the access entry.
*/
accessEntryArn;
cluster;
principal;
accessPolicies;
constructor(scope, id, props) {
super(scope, id);
try {
jsiiDeprecationWarnings._aws_cdk_aws_eks_v2_alpha_AccessEntryProps(props);
}
catch (error) {
if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") {
Error.captureStackTrace(error, AccessEntry);
}
throw error;
}
// Enhanced CDK Analytics Telemetry
(0, metadata_resource_1.addConstructMetadata)(this, props);
this.cluster = props.cluster;
this.principal = props.principal;
this.accessPolicies = props.accessPolicies;
const resource = new aws_eks_1.CfnAccessEntry(this, 'Resource', {
clusterName: this.cluster.clusterName,
principalArn: this.principal,
type: props.accessEntryType,
accessPolicies: core_1.Lazy.any({
produce: () => this.accessPolicies.map(p => ({
accessScope: {
type: p.accessScope.type,
namespaces: p.accessScope.namespaces,
},
policyArn: p.policy,
})),
}),
});
this.accessEntryName = this.getResourceNameAttribute(resource.ref);
this.accessEntryArn = this.getResourceArnAttribute(resource.attrAccessEntryArn, {
service: 'eks',
resource: 'accessentry',
resourceName: this.physicalName,
});
}
/**
* Add the access policies for this entry.
* @param newAccessPolicies - The new access policies to add.
*/
addAccessPolicies(newAccessPolicies) {
// add newAccessPolicies to this.accessPolicies
this.accessPolicies.push(...newAccessPolicies);
}
static {
__runInitializers(_classThis, _classExtraInitializers);
}
};
return AccessEntry = _classThis;
})();
exports.AccessEntry = AccessEntry;
//# sourceMappingURL=data:application/json;base64,{"version":3,"file":"access-entry.js","sourceRoot":"","sources":["access-entry.ts"],"names":[],"mappings":";;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;AAEA,iDAAqD;AACrD,2CAAkE;AAClE,8EAA8F;AAC9F,0EAA0E;AAuC1E;;;;;;;GAOG;AACH,IAAY,eASX;AATD,WAAY,eAAe;IACzB;;OAEG;IACH,0CAAuB,CAAA;IACvB;;OAEG;IACH,sCAAmB,CAAA;AACrB,CAAC,EATW,eAAe,+BAAf,eAAe,QAS1B;AAyBD;;;;;;GAMG;AACH,MAAa,eAAe;IAiDE;;IAhD5B;;;;OAIG;IACI,MAAM,CAAU,uBAAuB,GAAG,eAAe,CAAC,EAAE,CAAC,sBAAsB,CAAC,CAAC;IAE5F;;;;OAIG;IACI,MAAM,CAAU,+BAA+B,GAAG,eAAe,CAAC,EAAE,CAAC,6BAA6B,CAAC,CAAC;IAE3G;;;OAGG;IACI,MAAM,CAAU,4BAA4B,GAAG,eAAe,CAAC,EAAE,CAAC,0BAA0B,CAAC,CAAC;IAErG;;;OAGG;IACI,MAAM,CAAU,sBAAsB,GAAG,eAAe,CAAC,EAAE,CAAC,qBAAqB,CAAC,CAAC;IAE1F;;;OAGG;IACI,MAAM,CAAU,sBAAsB,GAAG,eAAe,CAAC,EAAE,CAAC,qBAAqB,CAAC,CAAC;IAE1F;;;;OAIG;IACI,MAAM,CAAC,EAAE,CAAC,UAAkB,IAAI,OAAO,IAAI,eAAe,CAAC,UAAU,CAAC,CAAC,EAAE;IAEhF;;OAEG;IACa,SAAS,CAAS;IAClC;;;;OAIG;IACH,YAA4B,UAAkB;QAAlB,eAAU,GAAV,UAAU,CAAQ;QAC5C,IAAI,CAAC,SAAS,GAAG,OAAO,UAAG,CAAC,SAAS,mCAAmC,UAAU,EAAE,CAAC;KACtF;;AAnDH,0CAoDC;AA+CD;;;;GAIG;AACH,MAAa,YAAY;;IACvB;;OAEG;IACI,MAAM,CAAC,oBAAoB,CAAC,UAAkB,EAAE,OAAgC;;;;;;;;;;QACrF,MAAM,MAAM;YACM,MAAM,GAAG,OAAO,UAAG,CAAC,SAAS,mCAAmC,UAAU,EAAE,CAAC;YAC7E,WAAW,GAAgB;gBACzC,IAAI,EAAE,OAAO,CAAC,eAAe;gBAC7B,UAAU,EAAE,OAAO,CAAC,UAAU;aAC/B,CAAC;SACH;QACD,OAAO,IAAI,MAAM,EAAE,CAAC;KACrB;IACD;;OAEG;IACa,WAAW,CAAc;IAEzC;;OAEG;IACa,MAAM,CAAS;IAE/B;;;;OAIG;IACH,YAAY,KAAwB;;;;;;+CA7BzB,YAAY;;;;QA8BrB,IAAI,CAAC,WAAW,GAAG,KAAK,CAAC,WAAW,CAAC;QACrC,IAAI,CAAC,MAAM,GAAG,KAAK,CAAC,MAAM,CAAC,SAAS,CAAC;KACtC;;AAhCH,oCAiCC;AAED;;;;GAIG;AACH,IAAY,eAoBX;AApBD,WAAY,eAAe;IACzB;;OAEG;IACH,wCAAqB,CAAA;IAErB;;OAEG;IACH,kDAA+B,CAAA;IAE/B;;OAEG;IACH,0CAAuB,CAAA;IAEvB;;OAEG;IACH,8CAA2B,CAAA;AAC7B,CAAC,EApBW,eAAe,+BAAf,eAAe,QAoB1B;AAgCD;;;;;;;GAOG;IAEU,WAAW;4BADvB,oCAAkB;;;;sBACc,eAAQ;;;2BAAhB,SAAQ,WAAQ;;;;6CAiEtC,IAAA,kCAAc,GAAE;YACjB,sMAAO,iBAAiB,6DAGvB;YArEH,6KAsEC;;;;;QArEC,sCAAsC;QAC/B,MAAM,CAAU,qBAAqB,GAAW,uCAAuC,CAAC;QAE/F;;;;;;;WAOG;QACI,MAAM,CAAC,yBAAyB,CAAC,KAAgB,EAAE,EAAU,EAAE,KAA4B;;;;;;;;;;YAChG,MAAM,MAAO,SAAQ,eAAQ;gBACX,eAAe,GAAG,KAAK,CAAC,eAAe,CAAC;gBACxC,cAAc,GAAG,KAAK,CAAC,cAAc,CAAC;aACvD;YACD,OAAO,IAAI,MAAM,CAAC,KAAK,EAAE,EAAE,CAAC,CAAC;SAC9B;QACD;;WAEG;QACa,eAAe,GAtBpB,mDAAW,CAsBkB;QACxC;;WAEG;QACa,cAAc,CAAS;QAC/B,OAAO,CAAW;QAClB,SAAS,CAAS;QAClB,cAAc,CAAkB;QAExC,YAAY,KAAgB,EAAE,EAAU,EAAE,KAAuB;YAC/D,KAAK,CAAC,KAAK,EAAE,EAAE,CAAC,CAAC;;;;;;mDAhCR,WAAW;;;;YAiCpB,mCAAmC;YACnC,IAAA,wCAAoB,EAAC,IAAI,EAAE,KAAK,CAAC,CAAC;YAElC,IAAI,CAAC,OAAO,GAAG,KAAK,CAAC,OAAO,CAAC;YAC7B,IAAI,CAAC,SAAS,GAAG,KAAK,CAAC,SAAS,CAAC;YACjC,IAAI,CAAC,cAAc,GAAG,KAAK,CAAC,cAAc,CAAC;YAE3C,MAAM,QAAQ,GAAG,IAAI,wBAAc,CAAC,IAAI,EAAE,UAAU,EAAE;gBACpD,WAAW,EAAE,IAAI,CAAC,OAAO,CAAC,WAAW;gBACrC,YAAY,EAAE,IAAI,CAAC,SAAS;gBAC5B,IAAI,EAAE,KAAK,CAAC,eAAe;gBAC3B,cAAc,EAAE,WAAI,CAAC,GAAG,CAAC;oBACvB,OAAO,EAAE,GAAG,EAAE,CAAC,IAAI,CAAC,cAAc,CAAC,GAAG,CAAC,CAAC,CAAC,EAAE,CAAC,CAAC;wBAC3C,WAAW,EAAE;4BACX,IAAI,EAAE,CAAC,CAAC,WAAW,CAAC,IAAI;4BACxB,UAAU,EAAE,CAAC,CAAC,WAAW,CAAC,UAAU;yBACrC;wBACD,SAAS,EAAE,CAAC,CAAC,MAAM;qBACpB,CAAC,CAAC;iBACJ,CAAC;aACH,CAAC,CAAC;YACH,IAAI,CAAC,eAAe,GAAG,IAAI,CAAC,wBAAwB,CAAC,QAAQ,CAAC,GAAG,CAAC,CAAC;YACnE,IAAI,CAAC,cAAc,GAAG,IAAI,CAAC,uBAAuB,CAAC,QAAQ,CAAC,kBAAkB,EAAE;gBAC9E,OAAO,EAAE,KAAK;gBACd,QAAQ,EAAE,aAAa;gBACvB,YAAY,EAAE,IAAI,CAAC,YAAY;aAChC,CAAC,CAAC;SACJ;QACD;;;WAGG;QAEI,iBAAiB,CAAC,iBAAkC;YACzD,+CAA+C;YAC/C,IAAI,CAAC,cAAc,CAAC,IAAI,CAAC,GAAG,iBAAiB,CAAC,CAAC;SAChD;;YArEU,uDAAW;;;;;AAAX,kCAAW","sourcesContent":["import { Construct } from 'constructs';\nimport { ICluster } from './cluster';\nimport { CfnAccessEntry } from 'aws-cdk-lib/aws-eks';\nimport { Resource, IResource, Aws, Lazy } from 'aws-cdk-lib/core';\nimport { MethodMetadata, addConstructMetadata } from 'aws-cdk-lib/core/lib/metadata-resource';\nimport { propertyInjectable } from 'aws-cdk-lib/core/lib/prop-injectable';\n\n/**\n * Represents an access entry in an Amazon EKS cluster.\n *\n * An access entry defines the permissions and scope for a user or role to access an Amazon EKS cluster.\n *\n * @interface IAccessEntry\n * @extends {IResource}\n * @property {string} accessEntryName - The name of the access entry.\n * @property {string} accessEntryArn - The Amazon Resource Name (ARN) of the access entry.\n */\nexport interface IAccessEntry extends IResource {\n  /**\n   * The name of the access entry.\n   * @attribute\n   */\n  readonly accessEntryName: string;\n  /**\n   * The Amazon Resource Name (ARN) of the access entry.\n   * @attribute\n   */\n  readonly accessEntryArn: string;\n}\n\n/**\n * Represents the attributes of an access entry.\n */\nexport interface AccessEntryAttributes {\n  /**\n   * The name of the access entry.\n   */\n  readonly accessEntryName: string;\n  /**\n   * The Amazon Resource Name (ARN) of the access entry.\n   */\n  readonly accessEntryArn: string;\n}\n\n/**\n * Represents the scope type of an access policy.\n *\n * The scope type determines the level of access granted by the policy.\n *\n * @export\n * @enum {string}\n */\nexport enum AccessScopeType {\n  /**\n   * The policy applies to a specific namespace within the cluster.\n   */\n  NAMESPACE = 'namespace',\n  /**\n   * The policy applies to the entire cluster.\n   */\n  CLUSTER = 'cluster',\n}\n\n/**\n * Represents the scope of an access policy.\n *\n * The scope defines the namespaces or cluster-level access granted by the policy.\n *\n * @interface AccessScope\n * @property {string[]} [namespaces] - The namespaces to which the policy applies, if the scope type is 'namespace'.\n * @property {AccessScopeType} type - The scope type of the policy, either 'namespace' or 'cluster'.\n */\nexport interface AccessScope {\n  /**\n   * A Kubernetes namespace that an access policy is scoped to. A value is required if you specified\n   * namespace for Type.\n   *\n   * @default - no specific namespaces for this scope.\n   */\n  readonly namespaces?: string[];\n  /**\n   * The scope type of the policy, either 'namespace' or 'cluster'.\n   */\n  readonly type: AccessScopeType;\n}\n\n/**\n * Represents an Amazon EKS Access Policy ARN.\n *\n * Amazon EKS Access Policies are used to control access to Amazon EKS clusters.\n *\n * @see https://docs.aws.amazon.com/eks/latest/userguide/access-policies.html\n */\nexport class AccessPolicyArn {\n  /**\n   * The Amazon EKS Admin Policy. This access policy includes permissions that grant an IAM principal\n   * most permissions to resources. When associated to an access entry, its access scope is typically\n   * one or more Kubernetes namespaces.\n   */\n  public static readonly AMAZON_EKS_ADMIN_POLICY = AccessPolicyArn.of('AmazonEKSAdminPolicy');\n\n  /**\n   * The Amazon EKS Cluster Admin Policy. This access policy includes permissions that grant an IAM\n   * principal administrator access to a cluster. When associated to an access entry, its access scope\n   * is typically the cluster, rather than a Kubernetes namespace.\n   */\n  public static readonly AMAZON_EKS_CLUSTER_ADMIN_POLICY = AccessPolicyArn.of('AmazonEKSClusterAdminPolicy');\n\n  /**\n   * The Amazon EKS Admin View Policy. This access policy includes permissions that grant an IAM principal\n   * access to list/view all resources in a cluster.\n   */\n  public static readonly AMAZON_EKS_ADMIN_VIEW_POLICY = AccessPolicyArn.of('AmazonEKSAdminViewPolicy');\n\n  /**\n   * The Amazon EKS Edit Policy. This access policy includes permissions that allow an IAM principal\n   * to edit most Kubernetes resources.\n   */\n  public static readonly AMAZON_EKS_EDIT_POLICY = AccessPolicyArn.of('AmazonEKSEditPolicy');\n\n  /**\n   * The Amazon EKS View Policy. This access policy includes permissions that grant an IAM principal\n   * access to list/view all resources in a cluster.\n   */\n  public static readonly AMAZON_EKS_VIEW_POLICY = AccessPolicyArn.of('AmazonEKSViewPolicy');\n\n  /**\n   * Creates a new instance of the AccessPolicy class with the specified policy name.\n   * @param policyName The name of the access policy.\n   * @returns A new instance of the AccessPolicy class.\n   */\n  public static of(policyName: string) { return new AccessPolicyArn(policyName); }\n\n  /**\n   * The Amazon Resource Name (ARN) of the access policy.\n   */\n  public readonly policyArn: string;\n  /**\n   * Constructs a new instance of the `AccessEntry` class.\n   *\n   * @param policyName - The name of the Amazon EKS access policy. This is used to construct the policy ARN.\n   */\n  constructor(public readonly policyName: string) {\n    this.policyArn = `arn:${Aws.PARTITION}:eks::aws:cluster-access-policy/${policyName}`;\n  }\n}\n\n/**\n * Represents an access policy that defines the permissions and scope for a user or role to access an Amazon EKS cluster.\n *\n * @interface IAccessPolicy\n */\nexport interface IAccessPolicy {\n  /**\n   * The scope of the access policy, which determines the level of access granted.\n   */\n  readonly accessScope: AccessScope;\n  /**\n   * The access policy itself, which defines the specific permissions.\n   */\n  readonly policy: string;\n}\n\n/**\n * Properties for configuring an Amazon EKS Access Policy.\n */\nexport interface AccessPolicyProps {\n  /**\n   * The scope of the access policy, which determines the level of access granted.\n   */\n  readonly accessScope: AccessScope;\n  /**\n   * The access policy itself, which defines the specific permissions.\n   */\n  readonly policy: AccessPolicyArn;\n}\n\n/**\n * Represents the options required to create an Amazon EKS Access Policy using the `fromAccessPolicyName()` method.\n */\nexport interface AccessPolicyNameOptions {\n  /**\n   * The scope of the access policy. This determines the level of access granted by the policy.\n   */\n  readonly accessScopeType: AccessScopeType;\n  /**\n   * An optional array of Kubernetes namespaces to which the access policy applies.\n   * @default - no specific namespaces for this scope\n   */\n  readonly namespaces?: string[];\n}\n\n/**\n * Represents an Amazon EKS Access Policy that implements the IAccessPolicy interface.\n *\n * @implements {IAccessPolicy}\n */\nexport class AccessPolicy implements IAccessPolicy {\n  /**\n   * Import AccessPolicy by name.\n   */\n  public static fromAccessPolicyName(policyName: string, options: AccessPolicyNameOptions): IAccessPolicy {\n    class Import implements IAccessPolicy {\n      public readonly policy = `arn:${Aws.PARTITION}:eks::aws:cluster-access-policy/${policyName}`;\n      public readonly accessScope: AccessScope = {\n        type: options.accessScopeType,\n        namespaces: options.namespaces,\n      };\n    }\n    return new Import();\n  }\n  /**\n   * The scope of the access policy, which determines the level of access granted.\n   */\n  public readonly accessScope: AccessScope;\n\n  /**\n   * The access policy itself, which defines the specific permissions.\n   */\n  public readonly policy: string;\n\n  /**\n   * Constructs a new instance of the AccessPolicy class.\n   *\n   * @param {AccessPolicyProps} props - The properties for configuring the access policy.\n   */\n  constructor(props: AccessPolicyProps) {\n    this.accessScope = props.accessScope;\n    this.policy = props.policy.policyArn;\n  }\n}\n\n/**\n * Represents the different types of access entries that can be used in an Amazon EKS cluster.\n *\n * @enum {string}\n */\nexport enum AccessEntryType {\n  /**\n   * Represents a standard access entry.\n   */\n  STANDARD = 'STANDARD',\n\n  /**\n   * Represents a Fargate Linux access entry.\n   */\n  FARGATE_LINUX = 'FARGATE_LINUX',\n\n  /**\n   * Represents an EC2 Linux access entry.\n   */\n  EC2_LINUX = 'EC2_LINUX',\n\n  /**\n   * Represents an EC2 Windows access entry.\n   */\n  EC2_WINDOWS = 'EC2_WINDOWS',\n}\n\n/**\n * Represents the properties required to create an Amazon EKS access entry.\n */\nexport interface AccessEntryProps {\n  /**\n   * The name of the AccessEntry.\n   *\n   * @default - No access entry name is provided\n   */\n  readonly accessEntryName?: string;\n  /**\n   * The type of the AccessEntry.\n   *\n   * @default STANDARD\n   */\n  readonly accessEntryType?: AccessEntryType;\n  /**\n   * The Amazon EKS cluster to which the access entry applies.\n   */\n  readonly cluster: ICluster;\n  /**\n   * The access policies that define the permissions and scope for the access entry.\n   */\n  readonly accessPolicies: IAccessPolicy[];\n  /**\n   * The Amazon Resource Name (ARN) of the principal (user or role) to associate the access entry with.\n   */\n  readonly principal: string;\n}\n\n/**\n * Represents an access entry in an Amazon EKS cluster.\n *\n * An access entry defines the permissions and scope for a user or role to access an Amazon EKS cluster.\n *\n * @implements {IAccessEntry}\n * @resource AWS::EKS::AccessEntry\n */\n@propertyInjectable\nexport class AccessEntry extends Resource implements IAccessEntry {\n  /** Uniquely identifies this class. */\n  public static readonly PROPERTY_INJECTION_ID: string = '@aws-cdk.aws-eks-v2-alpha.AccessEntry';\n\n  /**\n   * Imports an `AccessEntry` from its attributes.\n   *\n   * @param scope - The parent construct.\n   * @param id - The ID of the imported construct.\n   * @param attrs - The attributes of the access entry to import.\n   * @returns The imported access entry.\n   */\n  public static fromAccessEntryAttributes(scope: Construct, id: string, attrs: AccessEntryAttributes): IAccessEntry {\n    class Import extends Resource implements IAccessEntry {\n      public readonly accessEntryName = attrs.accessEntryName;\n      public readonly accessEntryArn = attrs.accessEntryArn;\n    }\n    return new Import(scope, id);\n  }\n  /**\n   * The name of the access entry.\n   */\n  public readonly accessEntryName: string;\n  /**\n   * The Amazon Resource Name (ARN) of the access entry.\n   */\n  public readonly accessEntryArn: string;\n  private cluster: ICluster;\n  private principal: string;\n  private accessPolicies: IAccessPolicy[];\n\n  constructor(scope: Construct, id: string, props: AccessEntryProps ) {\n    super(scope, id);\n    // Enhanced CDK Analytics Telemetry\n    addConstructMetadata(this, props);\n\n    this.cluster = props.cluster;\n    this.principal = props.principal;\n    this.accessPolicies = props.accessPolicies;\n\n    const resource = new CfnAccessEntry(this, 'Resource', {\n      clusterName: this.cluster.clusterName,\n      principalArn: this.principal,\n      type: props.accessEntryType,\n      accessPolicies: Lazy.any({\n        produce: () => this.accessPolicies.map(p => ({\n          accessScope: {\n            type: p.accessScope.type,\n            namespaces: p.accessScope.namespaces,\n          },\n          policyArn: p.policy,\n        })),\n      }),\n    });\n    this.accessEntryName = this.getResourceNameAttribute(resource.ref);\n    this.accessEntryArn = this.getResourceArnAttribute(resource.attrAccessEntryArn, {\n      service: 'eks',\n      resource: 'accessentry',\n      resourceName: this.physicalName,\n    });\n  }\n  /**\n   * Add the access policies for this entry.\n   * @param newAccessPolicies - The new access policies to add.\n   */\n  @MethodMetadata()\n  public addAccessPolicies(newAccessPolicies: IAccessPolicy[]): void {\n    // add newAccessPolicies to this.accessPolicies\n    this.accessPolicies.push(...newAccessPolicies);\n  }\n}\n"]}