getLogDeliveryCanonicalUserId function

Future<GetLogDeliveryCanonicalUserIdResult> getLogDeliveryCanonicalUserId(
  1. GetLogDeliveryCanonicalUserIdArgs args, {
  2. InvokeOptions? options,
})

The CloudFront Log Delivery Canonical User ID data source allows access to the canonical user ID of the AWS awslogsdelivery account for CloudFront bucket logging. See the Amazon CloudFront Developer Guide for more information.

Example Usage

import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";

const current = aws.s3.getCanonicalUserId({});
const example = aws.cloudfront.getLogDeliveryCanonicalUserId({});
const exampleBucket = new aws.s3.Bucket("example", {bucket: "example"});
const exampleBucketOwnershipControls = new aws.s3.BucketOwnershipControls("example", {
    rule: {
        objectOwnership: "BucketOwnerPreferred",
    },
    bucket: exampleBucket.id,
});
const exampleBucketAcl = new aws.s3.BucketAcl("example", {
    accessControlPolicy: {
        owner: {
            id: current.then(current => current.id),
        },
        grants: [{
            grantee: {
                id: example.then(example => example.id),
                type: "CanonicalUser",
            },
            permission: "FULL_CONTROL",
        }],
    },
    bucket: exampleBucket.id,
}, {
    dependsOn: [exampleBucketOwnershipControls],
});
import pulumi
import pulumi_aws as aws

current = aws.s3.get_canonical_user_id()
example = aws.cloudfront.get_log_delivery_canonical_user_id()
example_bucket = aws.s3.Bucket("example", bucket="example")
example_bucket_ownership_controls = aws.s3.BucketOwnershipControls("example",
    rule={
        "object_ownership": "BucketOwnerPreferred",
    },
    bucket=example_bucket.id)
example_bucket_acl = aws.s3.BucketAcl("example",
    access_control_policy={
        "owner": {
            "id": current.id,
        },
        "grants": [{
            "grantee": {
                "id": example.id,
                "type": "CanonicalUser",
            },
            "permission": "FULL_CONTROL",
        }],
    },
    bucket=example_bucket.id,
    opts = pulumi.ResourceOptions(depends_on=[example_bucket_ownership_controls]))
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;

return await Deployment.RunAsync(() =>
{
    var current = Aws.S3.GetCanonicalUserId.Invoke();

    var example = Aws.CloudFront.GetLogDeliveryCanonicalUserId.Invoke();

    var exampleBucket = new Aws.S3.Bucket("example", new()
    {
        BucketName = "example",
    });

    var exampleBucketOwnershipControls = new Aws.S3.BucketOwnershipControls("example", new()
    {
        Rule = new Aws.S3.Inputs.BucketOwnershipControlsRuleArgs
        {
            ObjectOwnership = "BucketOwnerPreferred",
        },
        Bucket = exampleBucket.Id,
    });

    var exampleBucketAcl = new Aws.S3.BucketAcl("example", new()
    {
        AccessControlPolicy = new Aws.S3.Inputs.BucketAclAccessControlPolicyArgs
        {
            Owner = new Aws.S3.Inputs.BucketAclAccessControlPolicyOwnerArgs
            {
                Id = current.Apply(getCanonicalUserIdResult => getCanonicalUserIdResult.Id),
            },
            Grants = new[]
            {
                new Aws.S3.Inputs.BucketAclAccessControlPolicyGrantArgs
                {
                    Grantee = new Aws.S3.Inputs.BucketAclAccessControlPolicyGrantGranteeArgs
                    {
                        Id = example.Apply(getLogDeliveryCanonicalUserIdResult => getLogDeliveryCanonicalUserIdResult.Id),
                        Type = "CanonicalUser",
                    },
                    Permission = "FULL_CONTROL",
                },
            },
        },
        Bucket = exampleBucket.Id,
    }, new CustomResourceOptions
    {
        DependsOn =
        {
            exampleBucketOwnershipControls,
        },
    });

});
package main

import (
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/cloudfront"
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/s3"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		current, err := s3.GetCanonicalUserId(ctx, map[string]interface{}{}, nil)
		if err != nil {
			return err
		}
		example, err := cloudfront.GetLogDeliveryCanonicalUserId(ctx, &cloudfront.GetLogDeliveryCanonicalUserIdArgs{}, nil)
		if err != nil {
			return err
		}
		exampleBucket, err := s3.NewBucket(ctx, "example", &s3.BucketArgs{
			Bucket: pulumi.String("example"),
		})
		if err != nil {
			return err
		}
		exampleBucketOwnershipControls, err := s3.NewBucketOwnershipControls(ctx, "example", &s3.BucketOwnershipControlsArgs{
			Rule: &s3.BucketOwnershipControlsRuleArgs{
				ObjectOwnership: pulumi.String("BucketOwnerPreferred"),
			},
			Bucket: exampleBucket.ID().ToIDOutput().ToStringOutput(),
		})
		if err != nil {
			return err
		}
		_, err = s3.NewBucketAcl(ctx, "example", &s3.BucketAclArgs{
			AccessControlPolicy: &s3.BucketAclAccessControlPolicyArgs{
				Owner: &s3.BucketAclAccessControlPolicyOwnerArgs{
					Id: pulumi.String(current.Id),
				},
				Grants: s3.BucketAclAccessControlPolicyGrantArray{
					&s3.BucketAclAccessControlPolicyGrantArgs{
						Grantee: &s3.BucketAclAccessControlPolicyGrantGranteeArgs{
							Id:   pulumi.String(example.Id),
							Type: pulumi.String("CanonicalUser"),
						},
						Permission: pulumi.String("FULL_CONTROL"),
					},
				},
			},
			Bucket: exampleBucket.ID().ToIDOutput().ToStringOutput(),
		}, pulumi.DependsOn([]pulumi.Resource{
			exampleBucketOwnershipControls,
		}))
		if err != nil {
			return err
		}
		return nil
	})
}
pulumi {
  required_providers {
    aws = {
      source = "pulumi/aws"
    }
  }
}

data "aws_s3_getcanonicaluserid" "current" {
}
data "aws_cloudfront_getlogdeliverycanonicaluserid" "example" {
}

resource "aws_s3_bucket" "example" {
  bucket = "example"
}
resource "aws_s3_bucketownershipcontrols" "example" {
  rule = {
    object_ownership = "BucketOwnerPreferred"
  }
  bucket = aws_s3_bucket.example.id
}
resource "aws_s3_bucketacl" "example" {
  depends_on = [aws_s3_bucketownershipcontrols.example]
  access_control_policy = {
    owner = {
      id = data.aws_s3_getcanonicaluserid.current.id
    }
    grants = [{
      "grantee" = {
        "id"   = data.aws_cloudfront_getlogdeliverycanonicaluserid.example.id
        "type" = "CanonicalUser"
      }
      "permission" = "FULL_CONTROL"
    }]
  }
  bucket = aws_s3_bucket.example.id
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.s3.S3Functions;
import com.pulumi.aws.cloudfront.CloudfrontFunctions;
import com.pulumi.aws.cloudfront.inputs.GetLogDeliveryCanonicalUserIdArgs;
import com.pulumi.aws.s3.Bucket;
import com.pulumi.aws.s3.BucketArgs;
import com.pulumi.aws.s3.BucketOwnershipControls;
import com.pulumi.aws.s3.BucketOwnershipControlsArgs;
import com.pulumi.aws.s3.inputs.BucketOwnershipControlsRuleArgs;
import com.pulumi.aws.s3.BucketAcl;
import com.pulumi.aws.s3.BucketAclArgs;
import com.pulumi.aws.s3.inputs.BucketAclAccessControlPolicyArgs;
import com.pulumi.aws.s3.inputs.BucketAclAccessControlPolicyOwnerArgs;
import com.pulumi.aws.s3.inputs.BucketAclAccessControlPolicyGrantArgs;
import com.pulumi.aws.s3.inputs.BucketAclAccessControlPolicyGrantGranteeArgs;
import com.pulumi.resources.CustomResourceOptions;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        final var current = S3Functions.getCanonicalUserId(%!v(PANIC=Format method: runtime error: invalid memory address or nil pointer dereference);

        final var example = CloudfrontFunctions.getLogDeliveryCanonicalUserId(GetLogDeliveryCanonicalUserIdArgs.builder()
            .build());

        var exampleBucket = new Bucket("exampleBucket", BucketArgs.builder()
            .bucket("example")
            .build());

        var exampleBucketOwnershipControls = new BucketOwnershipControls("exampleBucketOwnershipControls", BucketOwnershipControlsArgs.builder()
            .rule(BucketOwnershipControlsRuleArgs.builder()
                .objectOwnership("BucketOwnerPreferred")
                .build())
            .bucket(exampleBucket.id())
            .build());

        var exampleBucketAcl = new BucketAcl("exampleBucketAcl", BucketAclArgs.builder()
            .accessControlPolicy(BucketAclAccessControlPolicyArgs.builder()
                .owner(BucketAclAccessControlPolicyOwnerArgs.builder()
                    .id(current.id())
                    .build())
                .grants(BucketAclAccessControlPolicyGrantArgs.builder()
                    .grantee(BucketAclAccessControlPolicyGrantGranteeArgs.builder()
                        .id(example.id())
                        .type("CanonicalUser")
                        .build())
                    .permission("FULL_CONTROL")
                    .build())
                .build())
            .bucket(exampleBucket.id())
            .build(), CustomResourceOptions.builder()
                .dependsOn(exampleBucketOwnershipControls)
                .build());

    }
}
resources:
  exampleBucket:
    type: aws:s3:Bucket
    name: example
    properties:
      bucket: example
  exampleBucketOwnershipControls:
    type: aws:s3:BucketOwnershipControls
    name: example
    properties:
      rule:
        objectOwnership: BucketOwnerPreferred
      bucket: ${exampleBucket.id}
  exampleBucketAcl:
    type: aws:s3:BucketAcl
    name: example
    properties:
      accessControlPolicy:
        owner:
          id: ${current.id}
        grants:
          - grantee:
              id: ${example.id}
              type: CanonicalUser
            permission: FULL_CONTROL
      bucket: ${exampleBucket.id}
    options:
      dependsOn:
        - ${exampleBucketOwnershipControls}
variables:
  current:
    fn::invoke:
      function: aws:s3:getCanonicalUserId
      arguments: {}
  example:
    fn::invoke:
      function: aws:cloudfront:getLogDeliveryCanonicalUserId
      arguments: {}

args Arguments passed to this invoke. Arguments for getLogDeliveryCanonicalUserId. options Invoke options controlling this call.

Implementation

Future<GetLogDeliveryCanonicalUserIdResult> getLogDeliveryCanonicalUserId(
  GetLogDeliveryCanonicalUserIdArgs args, {
  pulumi.InvokeOptions? options,
}) async {
  final deployment = pulumi.Deployment.instance;
  final result = await deployment.invoke<Map<String, dynamic>>(
    'aws:cloudfront/getLogDeliveryCanonicalUserId:getLogDeliveryCanonicalUserId',
    args.toMap(),
    options: pulumi.toDeploymentInvokeOptions(options),
  );
  return GetLogDeliveryCanonicalUserIdResult.fromMap(result);
}