OriginAccessControl class

Manages an AWS CloudFront Origin Access Control, which is used by CloudFront Distributions with an Amazon S3 bucket as the origin.

Read more about Origin Access Control in the CloudFront Developer Guide.

Example Usage

Basic Usage

import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";

const example = new aws.cloudfront.OriginAccessControl("example", {
    name: "example",
    description: "Example Policy",
    originAccessControlOriginType: "s3",
    signingBehavior: "always",
    signingProtocol: "sigv4",
});
import pulumi
import pulumi_aws as aws

example = aws.cloudfront.OriginAccessControl("example",
    name="example",
    description="Example Policy",
    origin_access_control_origin_type="s3",
    signing_behavior="always",
    signing_protocol="sigv4")
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;

return await Deployment.RunAsync(() =>
{
    var example = new Aws.CloudFront.OriginAccessControl("example", new()
    {
        Name = "example",
        Description = "Example Policy",
        OriginAccessControlOriginType = "s3",
        SigningBehavior = "always",
        SigningProtocol = "sigv4",
    });

});
package main

import (
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/cloudfront"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		_, err := cloudfront.NewOriginAccessControl(ctx, "example", &cloudfront.OriginAccessControlArgs{
			Name:                          pulumi.String("example"),
			Description:                   pulumi.String("Example Policy"),
			OriginAccessControlOriginType: pulumi.String("s3"),
			SigningBehavior:               pulumi.String("always"),
			SigningProtocol:               pulumi.String("sigv4"),
		})
		if err != nil {
			return err
		}
		return nil
	})
}
pulumi {
  required_providers {
    aws = {
      source = "pulumi/aws"
    }
  }
}

resource "aws_cloudfront_originaccesscontrol" "example" {
  name                              = "example"
  description                       = "Example Policy"
  origin_access_control_origin_type = "s3"
  signing_behavior                  = "always"
  signing_protocol                  = "sigv4"
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.cloudfront.OriginAccessControl;
import com.pulumi.aws.cloudfront.OriginAccessControlArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        var example = new OriginAccessControl("example", OriginAccessControlArgs.builder()
            .name("example")
            .description("Example Policy")
            .originAccessControlOriginType("s3")
            .signingBehavior("always")
            .signingProtocol("sigv4")
            .build());

    }
}
resources:
  example:
    type: aws:cloudfront:OriginAccessControl
    properties:
      name: example
      description: Example Policy
      originAccessControlOriginType: s3
      signingBehavior: always
      signingProtocol: sigv4

Import

Using pulumi import, import CloudFront Origin Access Control using the id. For example:

$ pulumi import aws:cloudfront/originAccessControl:OriginAccessControl example E327GJI25M56DG

Constructors

OriginAccessControl(String name, {OriginAccessControlArgs? args, CustomResourceOptions? options})
Creates a new OriginAccessControl. name The Pulumi resource name. args Arguments used to configure this OriginAccessControl. The set of arguments for OriginAccessControl. options Resource options controlling this resource's behavior.
OriginAccessControl.reference(String urn)
Creates a typed reference to an existing OriginAccessControl resource.

Properties

arn ↔ Output<String>
The Origin Access Control ARN.
latefinal
childResources → Set<Resource>
finalinherited
completionSources ↔ Map<String, IOutputCompletionSource>
latefinalinherited
description ↔ Output<String?>
The description of the Origin Access Control. Defaults to "Managed by Pulumi" if omitted.
latefinal
etag ↔ Output<String>
The current version of this Origin Access Control.
latefinal
hashCode → int
The hash code for this object.
no setterinherited
id ↔ Output<String>
getter/setter pairinherited
isCustom → bool
Returns whether this resource is provider-managed.
no setterinherited
isProtected → bool
Returns whether this resource is protected from deletion.
no setterinherited
isRemote → bool
Whether this resource is registered as remote.
no setterinherited
isResourceReference → bool
Whether this instance represents a resource value returned over RPC.
finalinherited
name ↔ Output<String>
A name that identifies the Origin Access Control.
latefinal
originAccessControlOriginType ↔ Output<String>
The type of origin that this Origin Access Control is for. Valid values are lambda, mediapackagev2, mediastore, and s3.
latefinal
resourceTransforms → List<ResourceTransform>
Inherited/explicit async transforms.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
signingBehavior ↔ Output<String>
Specifies which requests CloudFront signs. Specify always for the most common use case. Allowed values: always, never, and no-override.
latefinal
signingProtocol ↔ Output<String>
Determines how CloudFront signs (authenticates) requests. The only valid value is sigv4.
latefinal
transformations → List<ResourceTransformation>
Inherited/explicit legacy transformations.
no setterinherited
urn ↔ Output<String>
latefinalinherited

Methods

failId(Object error) → void
Completes this resource ID with an error when registration fails.
inherited
failOutputs(Object error) → void
Completes all output properties with error.
inherited
failUrn(Object error) → void
Completes this resource URN with an error when registration fails.
inherited
getProvider(String moduleMember) → ProviderResource?
Returns provider for moduleMember's package, if configured.
inherited
getResourceName() → String
Returns this resource's logical name.
inherited
getResourceType() → String
Returns this resource's Pulumi type token.
inherited
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
registerOutput<T>(String propertyName, {Object? decoder(Object?)?, bool isSecret = false}) → Output<T>
Registers a dynamic output property for this resource.
inherited
resolveId(String? value, {required bool isKnown}) → void
Resolves the provider-assigned ID for this resource.
inherited
resolveOutputs(Struct outputs) → void
Resolves all output properties from a monitor response payload.
inherited
resolveUrn(String value) → void
Resolves this resource's URN once assigned by the engine.
inherited
serializeProperties(Map<String, dynamic> properties) → Future<Struct>
Serializes resource properties for RPC transmission.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

get(String name, Input<String> id, {OriginAccessControlState? state, CustomResourceOptions? options}) → OriginAccessControl
Gets an existing OriginAccessControl resource's state with the given name and id.