@pulumi/pulumiservice
Version:
[](https://slack.pulumi.com) [](https://www.npmjs.com/package/@pulumi/pulumiservice) [ || (Object.create ? (function(o, m, k, k2) {
if (k2 === undefined) k2 = k;
var desc = Object.getOwnPropertyDescriptor(m, k);
if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {
desc = { enumerable: true, get: function() { return m[k]; } };
}
Object.defineProperty(o, k2, desc);
}) : (function(o, m, k, k2) {
if (k2 === undefined) k2 = k;
o[k2] = m[k];
}));
var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {
Object.defineProperty(o, "default", { enumerable: true, value: v });
}) : function(o, v) {
o["default"] = v;
});
var __importStar = (this && this.__importStar) || function (mod) {
if (mod && mod.__esModule) return mod;
var result = {};
if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);
__setModuleDefault(result, mod);
return result;
};
Object.defineProperty(exports, "__esModule", { value: true });
exports.Role = void 0;
const pulumi = __importStar(require("@pulumi/pulumi"));
const utilities = __importStar(require("../utilities"));
/**
* Creates a new custom role for an organization. Custom roles define fine-grained permission sets that can be assigned to organization members and teams, enabling precise access control beyond the built-in admin and member roles. Optionally, an associated policy and role binding can be created alongside the role. Role definitions are subject to two limits: a permission descriptor group may contain at most 500 entries (each directly-specified entity counts as one entry), and the total serialized size of the role definition may not exceed 1 MB. Exceeding either limit returns a 400 error. If you need to grant access to more than 500 individually listed resources, use tag-based (ABAC) rules instead.
*/
class Role extends pulumi.CustomResource {
/**
* Get an existing Role resource's state with the given name, ID, and optional extra
* properties used to qualify the lookup.
*
* @param name The _unique_ name of the resulting resource.
* @param id The _unique_ provider ID of the resource to lookup.
* @param opts Optional settings to control the behavior of the CustomResource.
*/
static get(name, id, opts) {
return new Role(name, undefined, { ...opts, id: id });
}
/** @internal */
static __pulumiType = 'pulumiservice:api:Role';
/**
* Returns true if the given object is an instance of Role. This is designed to work even
* when multiple copies of the Pulumi SDK have been loaded into the same process.
*/
static isInstance(obj) {
if (obj === undefined || obj === null) {
return false;
}
return obj['__pulumiType'] === Role.__pulumiType;
}
/**
* Create a Role resource with the given unique name, arguments, and options.
*
* @param name The _unique_ name of the resource.
* @param args The arguments to use to populate this resource's properties.
* @param opts A bag of options that control this resource's behavior.
*/
constructor(name, args, opts) {
let resourceInputs = {};
opts = opts || {};
if (!opts.id) {
if (args?.orgName === undefined && !opts.urn) {
throw new Error("Missing required property 'orgName'");
}
resourceInputs["createPolicyAndRole"] = args?.createPolicyAndRole;
resourceInputs["description"] = args?.description;
resourceInputs["details"] = args?.details;
resourceInputs["name"] = args?.name;
resourceInputs["orgName"] = args?.orgName;
resourceInputs["resourceType"] = args?.resourceType;
resourceInputs["roleID"] = args?.roleID;
resourceInputs["uxPurpose"] = args?.uxPurpose;
resourceInputs["created"] = undefined /*out*/;
resourceInputs["defaultIdentifier"] = undefined /*out*/;
resourceInputs["isOrgDefault"] = undefined /*out*/;
resourceInputs["modified"] = undefined /*out*/;
resourceInputs["orgId"] = undefined /*out*/;
resourceInputs["version"] = undefined /*out*/;
}
else {
resourceInputs["created"] = undefined /*out*/;
resourceInputs["defaultIdentifier"] = undefined /*out*/;
resourceInputs["description"] = undefined /*out*/;
resourceInputs["details"] = undefined /*out*/;
resourceInputs["isOrgDefault"] = undefined /*out*/;
resourceInputs["modified"] = undefined /*out*/;
resourceInputs["name"] = undefined /*out*/;
resourceInputs["orgId"] = undefined /*out*/;
resourceInputs["resourceType"] = undefined /*out*/;
resourceInputs["roleID"] = undefined /*out*/;
resourceInputs["uxPurpose"] = undefined /*out*/;
resourceInputs["version"] = undefined /*out*/;
}
opts = pulumi.mergeOptions(utilities.resourceOptsDefaults(), opts);
super(Role.__pulumiType, name, resourceInputs, opts);
}
}
exports.Role = Role;
//# sourceMappingURL=role.js.map