@pulumi/azuredevops
Version:
A Pulumi package for creating and managing Azure DevOps.
197 lines • 7.65 kB
JavaScript
;
// *** WARNING: this file was generated by pulumi-language-nodejs. ***
// *** Do not edit by hand unless you're certain you know what you are doing! ***
Object.defineProperty(exports, "__esModule", { value: true });
exports.WorkItemQueryPermissions = void 0;
const pulumi = require("@pulumi/pulumi");
const utilities = require("./utilities");
/**
* Manages permissions for Work Item Queries.
*
* > **Note** Permissions can be assigned to group principals and not to single user principals.
*
* ## Permission levels
*
* Permission for Work Item Queries within Azure DevOps can be applied on two different levels.
* Those levels are reflected by specifying (or omitting) values for the arguments `projectId` and `path`.
*
* ### Project level
*
* Permissions for all Work Item Queries inside a project (existing or newly created ones) are specified, if only the argument `projectId` has a value.
*
* #### Example usage
*
* ```typescript
* import * as pulumi from "@pulumi/pulumi";
* import * as azuredevops from "@pulumi/azuredevops";
*
* const example = new azuredevops.Project("example", {
* name: "Example Project",
* workItemTemplate: "Agile",
* versionControl: "Git",
* visibility: "private",
* description: "Managed by Pulumi",
* });
* const example_readers = azuredevops.getGroupOutput({
* projectId: example.id,
* name: "Readers",
* });
* const project_wiq_root_permissions = new azuredevops.WorkItemQueryPermissions("project-wiq-root-permissions", {
* projectId: example.id,
* principal: example_readers.apply(example_readers => example_readers.id),
* permissions: {
* CreateRepository: "Deny",
* DeleteRepository: "Deny",
* RenameRepository: "NotSet",
* },
* });
* ```
*
* ### Shared Queries folder level
*
* Permissions for a specific folder inside Shared Queries are specified if the arguments `projectId` and `path` are set.
*
* > **Note** To set permissions for the Shared Queries folder itself use `/` as path value
*
* #### Example usage
*
* ```typescript
* import * as pulumi from "@pulumi/pulumi";
* import * as azuredevops from "@pulumi/azuredevops";
*
* const example = new azuredevops.Project("example", {
* name: "Example Project",
* workItemTemplate: "Agile",
* versionControl: "Git",
* visibility: "private",
* description: "Managed by Pulumi",
* });
* const example_readers = azuredevops.getGroupOutput({
* projectId: example.id,
* name: "Readers",
* });
* const example_permissions = new azuredevops.WorkItemQueryPermissions("example-permissions", {
* projectId: example.id,
* path: "/Team",
* principal: example_readers.apply(example_readers => example_readers.id),
* permissions: {
* Contribute: "Allow",
* Delete: "Deny",
* Read: "NotSet",
* },
* });
* ```
*
* ## Example Usage
*
* ```typescript
* import * as pulumi from "@pulumi/pulumi";
* import * as azuredevops from "@pulumi/azuredevops";
*
* const example = new azuredevops.Project("example", {
* name: "Example Project",
* workItemTemplate: "Agile",
* versionControl: "Git",
* visibility: "private",
* description: "Managed by Pulumi",
* });
* const example_readers = azuredevops.getGroupOutput({
* projectId: example.id,
* name: "Readers",
* });
* const example_contributors = azuredevops.getGroupOutput({
* projectId: example.id,
* name: "Contributors",
* });
* const example_project_permissions = new azuredevops.WorkItemQueryPermissions("example-project-permissions", {
* projectId: example.id,
* principal: example_readers.apply(example_readers => example_readers.id),
* permissions: {
* Read: "Allow",
* Delete: "Deny",
* Contribute: "Deny",
* ManagePermissions: "Deny",
* },
* });
* const example_sharedqueries_permissions = new azuredevops.WorkItemQueryPermissions("example-sharedqueries-permissions", {
* projectId: example.id,
* path: "/",
* principal: example_contributors.apply(example_contributors => example_contributors.id),
* permissions: {
* Read: "Allow",
* Delete: "Deny",
* },
* });
* ```
*
* ## Relevant Links
*
* * [Azure DevOps Service REST API 7.0 - Security](https://docs.microsoft.com/en-us/rest/api/azure/devops/security/?view=azure-devops-rest-7.0)
*
* ## PAT Permissions Required
*
* - **Project & Team**: vso.security_manage - Grants the ability to read, write, and manage security permissions.
*
* ## Import
*
* The resource does not support import.
*/
class WorkItemQueryPermissions extends pulumi.CustomResource {
/**
* Get an existing WorkItemQueryPermissions resource's state with the given name, ID, and optional extra
* properties used to qualify the lookup.
*
* @param name The _unique_ name of the resulting resource.
* @param id The _unique_ provider ID of the resource to lookup.
* @param state Any extra arguments used during the lookup.
* @param opts Optional settings to control the behavior of the CustomResource.
*/
static get(name, id, state, opts) {
return new WorkItemQueryPermissions(name, state, Object.assign(Object.assign({}, opts), { id: id }));
}
/**
* Returns true if the given object is an instance of WorkItemQueryPermissions. This is designed to work even
* when multiple copies of the Pulumi SDK have been loaded into the same process.
*/
static isInstance(obj) {
if (obj === undefined || obj === null) {
return false;
}
return obj['__pulumiType'] === WorkItemQueryPermissions.__pulumiType;
}
constructor(name, argsOrState, opts) {
let resourceInputs = {};
opts = opts || {};
if (opts.id) {
const state = argsOrState;
resourceInputs["path"] = state ? state.path : undefined;
resourceInputs["permissions"] = state ? state.permissions : undefined;
resourceInputs["principal"] = state ? state.principal : undefined;
resourceInputs["projectId"] = state ? state.projectId : undefined;
resourceInputs["replace"] = state ? state.replace : undefined;
}
else {
const args = argsOrState;
if ((!args || args.permissions === undefined) && !opts.urn) {
throw new Error("Missing required property 'permissions'");
}
if ((!args || args.principal === undefined) && !opts.urn) {
throw new Error("Missing required property 'principal'");
}
if ((!args || args.projectId === undefined) && !opts.urn) {
throw new Error("Missing required property 'projectId'");
}
resourceInputs["path"] = args ? args.path : undefined;
resourceInputs["permissions"] = args ? args.permissions : undefined;
resourceInputs["principal"] = args ? args.principal : undefined;
resourceInputs["projectId"] = args ? args.projectId : undefined;
resourceInputs["replace"] = args ? args.replace : undefined;
}
opts = pulumi.mergeOptions(utilities.resourceOptsDefaults(), opts);
super(WorkItemQueryPermissions.__pulumiType, name, resourceInputs, opts);
}
}
exports.WorkItemQueryPermissions = WorkItemQueryPermissions;
/** @internal */
WorkItemQueryPermissions.__pulumiType = 'azuredevops:index/workItemQueryPermissions:WorkItemQueryPermissions';
//# sourceMappingURL=workItemQueryPermissions.js.map