DataSource class

Provides an AppSync Data Source.

Example Usage

import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";

const exampleTable = new aws.dynamodb.Table("example", {
    attributes: [{
        name: "UserId",
        type: "S",
    }],
    name: "example",
    readCapacity: 1,
    writeCapacity: 1,
    hashKey: "UserId",
});
const assumeRole = aws.iam.getPolicyDocument({
    statements: [{
        principals: [{
            type: "Service",
            identifiers: ["appsync.amazonaws.com"],
        }],
        effect: "Allow",
        actions: ["sts:AssumeRole"],
    }],
});
const exampleRole = new aws.iam.Role("example", {
    name: "example",
    assumeRolePolicy: assumeRole.then(assumeRole => assumeRole.json),
});
const example = aws.iam.getPolicyDocumentOutput({
    statements: [{
        effect: "Allow",
        actions: ["dynamodb:*"],
        resources: [exampleTable.arn],
    }],
});
const exampleRolePolicy = new aws.iam.RolePolicy("example", {
    name: "example",
    role: exampleRole.id,
    policy: example.json,
});
const exampleGraphQLApi = new aws.appsync.GraphQLApi("example", {
    authenticationType: "API_KEY",
    name: "my_appsync_example",
});
const exampleDataSource = new aws.appsync.DataSource("example", {
    dynamodbConfig: {
        tableName: exampleTable.name,
    },
    apiId: exampleGraphQLApi.id,
    name: "my_appsync_example",
    serviceRoleArn: exampleRole.arn,
    type: "AMAZON_DYNAMODB",
});
import pulumi
import pulumi_aws as aws

example_table = aws.dynamodb.Table("example",
    attributes=[{
        "name": "UserId",
        "type": "S",
    }],
    name="example",
    read_capacity=1,
    write_capacity=1,
    hash_key="UserId")
assume_role = aws.iam.get_policy_document(statements=[{
    "principals": [{
        "type": "Service",
        "identifiers": ["appsync.amazonaws.com"],
    }],
    "effect": "Allow",
    "actions": ["sts:AssumeRole"],
}])
example_role = aws.iam.Role("example",
    name="example",
    assume_role_policy=assume_role.json)
example = aws.iam.get_policy_document_output(statements=[{
    "effect": "Allow",
    "actions": ["dynamodb:*"],
    "resources": [example_table.arn],
}])
example_role_policy = aws.iam.RolePolicy("example",
    name="example",
    role=example_role.id,
    policy=example.json)
example_graph_ql_api = aws.appsync.GraphQLApi("example",
    authentication_type="API_KEY",
    name="my_appsync_example")
example_data_source = aws.appsync.DataSource("example",
    dynamodb_config={
        "table_name": example_table.name,
    },
    api_id=example_graph_ql_api.id,
    name="my_appsync_example",
    service_role_arn=example_role.arn,
    type="AMAZON_DYNAMODB")
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;

return await Deployment.RunAsync(() =>
{
    var exampleTable = new Aws.DynamoDB.Table("example", new()
    {
        Attributes = new[]
        {
            new Aws.DynamoDB.Inputs.TableAttributeArgs
            {
                Name = "UserId",
                Type = "S",
            },
        },
        Name = "example",
        ReadCapacity = 1,
        WriteCapacity = 1,
        HashKey = "UserId",
    });

    var assumeRole = Aws.Iam.GetPolicyDocument.Invoke(new()
    {
        Statements = new[]
        {
            new Aws.Iam.Inputs.GetPolicyDocumentStatementInputArgs
            {
                Principals = new[]
                {
                    new Aws.Iam.Inputs.GetPolicyDocumentStatementPrincipalInputArgs
                    {
                        Type = "Service",
                        Identifiers = new[]
                        {
                            "appsync.amazonaws.com",
                        },
                    },
                },
                Effect = "Allow",
                Actions = new[]
                {
                    "sts:AssumeRole",
                },
            },
        },
    });

    var exampleRole = new Aws.Iam.Role("example", new()
    {
        Name = "example",
        AssumeRolePolicy = assumeRole.Apply(getPolicyDocumentResult => getPolicyDocumentResult.Json),
    });

    var example = Aws.Iam.GetPolicyDocument.Invoke(new()
    {
        Statements = new[]
        {
            new Aws.Iam.Inputs.GetPolicyDocumentStatementInputArgs
            {
                Effect = "Allow",
                Actions = new[]
                {
                    "dynamodb:*",
                },
                Resources = new[]
                {
                    exampleTable.Arn,
                },
            },
        },
    });

    var exampleRolePolicy = new Aws.Iam.RolePolicy("example", new()
    {
        Name = "example",
        Role = exampleRole.Id,
        Policy = example.Apply(getPolicyDocumentResult => getPolicyDocumentResult.Json),
    });

    var exampleGraphQLApi = new Aws.AppSync.GraphQLApi("example", new()
    {
        AuthenticationType = "API_KEY",
        Name = "my_appsync_example",
    });

    var exampleDataSource = new Aws.AppSync.DataSource("example", new()
    {
        DynamodbConfig = new Aws.AppSync.Inputs.DataSourceDynamodbConfigArgs
        {
            TableName = exampleTable.Name,
        },
        ApiId = exampleGraphQLApi.Id,
        Name = "my_appsync_example",
        ServiceRoleArn = exampleRole.Arn,
        Type = "AMAZON_DYNAMODB",
    });

});
package main

import (
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/appsync"
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/dynamodb"
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/iam"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		exampleTable, err := dynamodb.NewTable(ctx, "example", &dynamodb.TableArgs{
			Attributes: dynamodb.TableAttributeArray{
				&dynamodb.TableAttributeArgs{
					Name: pulumi.String("UserId"),
					Type: pulumi.String("S"),
				},
			},
			Name:          pulumi.String("example"),
			ReadCapacity:  pulumi.Int(1),
			WriteCapacity: pulumi.Int(1),
			HashKey:       pulumi.String("UserId"),
		})
		if err != nil {
			return err
		}
		assumeRole, err := iam.GetPolicyDocument(ctx, &iam.GetPolicyDocumentArgs{
			Statements: []iam.GetPolicyDocumentStatement{
				{
					Principals: []iam.GetPolicyDocumentStatementPrincipal{
						{
							Type: "Service",
							Identifiers: []string{
								"appsync.amazonaws.com",
							},
						},
					},
					Effect: pulumi.StringRef("Allow"),
					Actions: []string{
						"sts:AssumeRole",
					},
				},
			},
		}, nil)
		if err != nil {
			return err
		}
		exampleRole, err := iam.NewRole(ctx, "example", &iam.RoleArgs{
			Name:             pulumi.String("example"),
			AssumeRolePolicy: pulumi.String(assumeRole.Json),
		})
		if err != nil {
			return err
		}
		example := iam.GetPolicyDocumentOutput(ctx, iam.GetPolicyDocumentOutputArgs{
			Statements: iam.GetPolicyDocumentStatementArray{
				&iam.GetPolicyDocumentStatementArgs{
					Effect: pulumi.String("Allow"),
					Actions: pulumi.StringArray{
						pulumi.String("dynamodb:*"),
					},
					Resources: pulumi.StringArray{
						exampleTable.Arn,
					},
				},
			},
		}, nil)
		_, err = iam.NewRolePolicy(ctx, "example", &iam.RolePolicyArgs{
			Name:   pulumi.String("example"),
			Role:   exampleRole.ID().ToIDOutput().ToStringOutput(),
			Policy: example.Json(),
		})
		if err != nil {
			return err
		}
		exampleGraphQLApi, err := appsync.NewGraphQLApi(ctx, "example", &appsync.GraphQLApiArgs{
			AuthenticationType: pulumi.String("API_KEY"),
			Name:               pulumi.String("my_appsync_example"),
		})
		if err != nil {
			return err
		}
		_, err = appsync.NewDataSource(ctx, "example", &appsync.DataSourceArgs{
			DynamodbConfig: &appsync.DataSourceDynamodbConfigArgs{
				TableName: exampleTable.Name,
			},
			ApiId:          exampleGraphQLApi.ID().ToIDOutput().ToStringOutput(),
			Name:           pulumi.String("my_appsync_example"),
			ServiceRoleArn: exampleRole.Arn,
			Type:           pulumi.String("AMAZON_DYNAMODB"),
		})
		if err != nil {
			return err
		}
		return nil
	})
}
pulumi {
  required_providers {
    aws = {
      source = "pulumi/aws"
    }
  }
}

data "aws_iam_getpolicydocument" "assumeRole" {
  statements {
    principals {
      type        = "Service"
      identifiers = ["appsync.amazonaws.com"]
    }
    effect  = "Allow"
    actions = ["sts:AssumeRole"]
  }
}
data "aws_iam_getpolicydocument" "example" {
  statements {
    effect    = "Allow"
    actions   = ["dynamodb:*"]
    resources = [aws_dynamodb_table.example.arn]
  }
}

resource "aws_dynamodb_table" "example" {
  attributes {
    name = "UserId"
    type = "S"
  }
  name           = "example"
  read_capacity  = 1
  write_capacity = 1
  hash_key       = "UserId"
}
resource "aws_iam_role" "example" {
  name               = "example"
  assume_role_policy = data.aws_iam_getpolicydocument.assumeRole.json
}
resource "aws_iam_rolepolicy" "example" {
  name   = "example"
  role   = aws_iam_role.example.id
  policy = data.aws_iam_getpolicydocument.example.json
}
resource "aws_appsync_graphqlapi" "example" {
  authentication_type = "API_KEY"
  name                = "my_appsync_example"
}
resource "aws_appsync_datasource" "example" {
  dynamodb_config = {
    table_name = aws_dynamodb_table.example.name
  }
  api_id           = aws_appsync_graphqlapi.example.id
  name             = "my_appsync_example"
  service_role_arn = aws_iam_role.example.arn
  type             = "AMAZON_DYNAMODB"
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.dynamodb.Table;
import com.pulumi.aws.dynamodb.TableArgs;
import com.pulumi.aws.dynamodb.inputs.TableAttributeArgs;
import com.pulumi.aws.iam.IamFunctions;
import com.pulumi.aws.iam.inputs.GetPolicyDocumentArgs;
import com.pulumi.aws.iam.inputs.GetPolicyDocumentStatementArgs;
import com.pulumi.aws.iam.inputs.GetPolicyDocumentStatementPrincipalArgs;
import com.pulumi.aws.iam.Role;
import com.pulumi.aws.iam.RoleArgs;
import com.pulumi.aws.iam.RolePolicy;
import com.pulumi.aws.iam.RolePolicyArgs;
import com.pulumi.aws.appsync.GraphQLApi;
import com.pulumi.aws.appsync.GraphQLApiArgs;
import com.pulumi.aws.appsync.DataSource;
import com.pulumi.aws.appsync.DataSourceArgs;
import com.pulumi.aws.appsync.inputs.DataSourceDynamodbConfigArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        var exampleTable = new Table("exampleTable", TableArgs.builder()
            .attributes(TableAttributeArgs.builder()
                .name("UserId")
                .type("S")
                .build())
            .name("example")
            .readCapacity(1)
            .writeCapacity(1)
            .hashKey("UserId")
            .build());

        final var assumeRole = IamFunctions.getPolicyDocument(GetPolicyDocumentArgs.builder()
            .statements(GetPolicyDocumentStatementArgs.builder()
                .principals(GetPolicyDocumentStatementPrincipalArgs.builder()
                    .type("Service")
                    .identifiers("appsync.amazonaws.com")
                    .build())
                .effect("Allow")
                .actions("sts:AssumeRole")
                .build())
            .build());

        var exampleRole = new Role("exampleRole", RoleArgs.builder()
            .name("example")
            .assumeRolePolicy(assumeRole.json())
            .build());

        final var example = IamFunctions.getPolicyDocument(GetPolicyDocumentArgs.builder()
            .statements(GetPolicyDocumentStatementArgs.builder()
                .effect("Allow")
                .actions("dynamodb:*")
                .resources(exampleTable.arn())
                .build())
            .build());

        var exampleRolePolicy = new RolePolicy("exampleRolePolicy", RolePolicyArgs.builder()
            .name("example")
            .role(exampleRole.id())
            .policy(example.applyValue(_example -> _example.json()))
            .build());

        var exampleGraphQLApi = new GraphQLApi("exampleGraphQLApi", GraphQLApiArgs.builder()
            .authenticationType("API_KEY")
            .name("my_appsync_example")
            .build());

        var exampleDataSource = new DataSource("exampleDataSource", DataSourceArgs.builder()
            .dynamodbConfig(DataSourceDynamodbConfigArgs.builder()
                .tableName(exampleTable.name())
                .build())
            .apiId(exampleGraphQLApi.id())
            .name("my_appsync_example")
            .serviceRoleArn(exampleRole.arn())
            .type("AMAZON_DYNAMODB")
            .build());

    }
}
resources:
  exampleTable:
    type: aws:dynamodb:Table
    name: example
    properties:
      attributes:
        - name: UserId
          type: S
      name: example
      readCapacity: 1
      writeCapacity: 1
      hashKey: UserId
  exampleRole:
    type: aws:iam:Role
    name: example
    properties:
      name: example
      assumeRolePolicy: ${assumeRole.json}
  exampleRolePolicy:
    type: aws:iam:RolePolicy
    name: example
    properties:
      name: example
      role: ${exampleRole.id}
      policy: ${example.json}
  exampleGraphQLApi:
    type: aws:appsync:GraphQLApi
    name: example
    properties:
      authenticationType: API_KEY
      name: my_appsync_example
  exampleDataSource:
    type: aws:appsync:DataSource
    name: example
    properties:
      dynamodbConfig:
        tableName: ${exampleTable.name}
      apiId: ${exampleGraphQLApi.id}
      name: my_appsync_example
      serviceRoleArn: ${exampleRole.arn}
      type: AMAZON_DYNAMODB
variables:
  assumeRole:
    fn::invoke:
      function: aws:iam:getPolicyDocument
      arguments:
        statements:
          - principals:
              - type: Service
                identifiers:
                  - appsync.amazonaws.com
            effect: Allow
            actions:
              - sts:AssumeRole
  example:
    fn::invoke:
      function: aws:iam:getPolicyDocument
      arguments:
        statements:
          - effect: Allow
            actions:
              - dynamodb:*
            resources:
              - ${exampleTable.arn}

Import

Using pulumi import, import aws.appsync.DataSource using the apiId, a hyphen, and name. For example:

$ pulumi import aws:appsync/dataSource:DataSource example abcdef123456-example

Constructors

DataSource(String name, {DataSourceArgs? args, CustomResourceOptions? options})
Creates a new DataSource. name The Pulumi resource name. args Arguments used to configure this DataSource. The set of arguments for DataSource. options Resource options controlling this resource's behavior.
DataSource.reference(String urn)
Creates a typed reference to an existing DataSource resource.

Properties

apiId ↔ Output<String>
API ID for the GraphQL API for the data source.
latefinal
arn ↔ Output<String>
ARN
latefinal
childResources → Set<Resource>
finalinherited
completionSources ↔ Map<String, IOutputCompletionSource>
latefinalinherited
description ↔ Output<String?>
Description of the data source.
latefinal
dynamodbConfig ↔ Output<DataSourceDynamodbConfig?>
DynamoDB settings. See dynamodbConfig Block for details.
latefinal
elasticsearchConfig ↔ Output<DataSourceElasticsearchConfig?>
Amazon Elasticsearch settings. See elasticsearchConfig Block for details.
latefinal
eventBridgeConfig ↔ Output<DataSourceEventBridgeConfig?>
AWS EventBridge settings. See eventBridgeConfig Block for details.
latefinal
hashCode → int
The hash code for this object.
no setterinherited
httpConfig ↔ Output<DataSourceHttpConfig?>
HTTP settings. See httpConfig Block for details.
latefinal
id ↔ Output<String>
getter/setter pairinherited
isCustom → bool
Returns whether this resource is provider-managed.
no setterinherited
isProtected → bool
Returns whether this resource is protected from deletion.
no setterinherited
isRemote → bool
Whether this resource is registered as remote.
no setterinherited
isResourceReference → bool
Whether this instance represents a resource value returned over RPC.
finalinherited
lambdaConfig ↔ Output<DataSourceLambdaConfig?>
AWS Lambda settings. See lambdaConfig Block for details.
latefinal
name ↔ Output<String>
User-supplied name for the data source.
latefinal
opensearchserviceConfig ↔ Output<DataSourceOpensearchserviceConfig?>
Amazon OpenSearch Service settings. See opensearchserviceConfig Block for details.
latefinal
region ↔ Output<String>
Region where this resource will be managed. Defaults to the Region set in the provider configuration.
latefinal
relationalDatabaseConfig ↔ Output<DataSourceRelationalDatabaseConfig?>
AWS RDS settings. See relationalDatabaseConfig Block for details.
latefinal
resourceTransforms → List<ResourceTransform>
Inherited/explicit async transforms.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
serviceRoleArn ↔ Output<String?>
IAM service role ARN for the data source. Required if type is specified as AWS_LAMBDA, AMAZON_DYNAMODB, AMAZON_ELASTICSEARCH, AMAZON_EVENTBRIDGE, or AMAZON_OPENSEARCH_SERVICE.
latefinal
transformations → List<ResourceTransformation>
Inherited/explicit legacy transformations.
no setterinherited
type ↔ Output<String>
Type of the Data Source. Valid values: AWS_LAMBDA, AMAZON_DYNAMODB, AMAZON_ELASTICSEARCH, HTTP, NONE, RELATIONAL_DATABASE, AMAZON_EVENTBRIDGE, AMAZON_OPENSEARCH_SERVICE.
latefinal
urn ↔ Output<String>
latefinalinherited

Methods

failId(Object error) → void
Completes this resource ID with an error when registration fails.
inherited
failOutputs(Object error) → void
Completes all output properties with error.
inherited
failUrn(Object error) → void
Completes this resource URN with an error when registration fails.
inherited
getProvider(String moduleMember) → ProviderResource?
Returns provider for moduleMember's package, if configured.
inherited
getResourceName() → String
Returns this resource's logical name.
inherited
getResourceType() → String
Returns this resource's Pulumi type token.
inherited
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
registerOutput<T>(String propertyName, {Object? decoder(Object?)?, bool isSecret = false}) → Output<T>
Registers a dynamic output property for this resource.
inherited
resolveId(String? value, {required bool isKnown}) → void
Resolves the provider-assigned ID for this resource.
inherited
resolveOutputs(Struct outputs) → void
Resolves all output properties from a monitor response payload.
inherited
resolveUrn(String value) → void
Resolves this resource's URN once assigned by the engine.
inherited
serializeProperties(Map<String, dynamic> properties) → Future<Struct>
Serializes resource properties for RPC transmission.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

get(String name, Input<String> id, {DataSourceState? state, CustomResourceOptions? options}) → DataSource
Gets an existing DataSource resource's state with the given name and id.