NetworkInterfacePermission class

Grant cross-account access to an Elastic network interface (ENI).

Example Usage

import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";

const example = new aws.ec2.NetworkInterface("example", {
    attachments: [{
        instance: exampleAwsInstance.id,
        deviceIndex: 1,
    }],
    subnetId: exampleAwsSubnet.id,
    privateIps: ["10.0.0.50"],
    securityGroups: [exampleAwsSecurityGroup.id],
});
const exampleNetworkInterfacePermission = new aws.ec2.NetworkInterfacePermission("example", {
    networkInterfaceId: example.id,
    awsAccountId: "123456789012",
    permission: "INSTANCE-ATTACH",
});
import pulumi
import pulumi_aws as aws

example = aws.ec2.NetworkInterface("example",
    attachments=[{
        "instance": example_aws_instance["id"],
        "device_index": 1,
    }],
    subnet_id=example_aws_subnet["id"],
    private_ips=["10.0.0.50"],
    security_groups=[example_aws_security_group["id"]])
example_network_interface_permission = aws.ec2.NetworkInterfacePermission("example",
    network_interface_id=example.id,
    aws_account_id="123456789012",
    permission="INSTANCE-ATTACH")
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;

return await Deployment.RunAsync(() =>
{
    var example = new Aws.Ec2.NetworkInterface("example", new()
    {
        Attachments = new[]
        {
            new Aws.Ec2.Inputs.NetworkInterfaceAttachmentArgs
            {
                Instance = exampleAwsInstance.Id,
                DeviceIndex = 1,
            },
        },
        SubnetId = exampleAwsSubnet.Id,
        PrivateIps = new[]
        {
            "10.0.0.50",
        },
        SecurityGroups = new[]
        {
            exampleAwsSecurityGroup.Id,
        },
    });

    var exampleNetworkInterfacePermission = new Aws.Ec2.NetworkInterfacePermission("example", new()
    {
        NetworkInterfaceId = example.Id,
        AwsAccountId = "123456789012",
        Permission = "INSTANCE-ATTACH",
    });

});
package main

import (
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/ec2"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		example, err := ec2.NewNetworkInterface(ctx, "example", &ec2.NetworkInterfaceArgs{
			Attachments: ec2.NetworkInterfaceAttachmentTypeArray{
				&ec2.NetworkInterfaceAttachmentTypeArgs{
					Instance:    pulumi.Any(exampleAwsInstance.Id),
					DeviceIndex: pulumi.Int(1),
				},
			},
			SubnetId: pulumi.Any(exampleAwsSubnet.Id),
			PrivateIps: pulumi.StringArray{
				pulumi.String("10.0.0.50"),
			},
			SecurityGroups: pulumi.StringArray{
				exampleAwsSecurityGroup.Id,
			},
		})
		if err != nil {
			return err
		}
		_, err = ec2.NewNetworkInterfacePermission(ctx, "example", &ec2.NetworkInterfacePermissionArgs{
			NetworkInterfaceId: example.ID().ToIDOutput().ToStringOutput(),
			AwsAccountId:       pulumi.String("123456789012"),
			Permission:         pulumi.String("INSTANCE-ATTACH"),
		})
		if err != nil {
			return err
		}
		return nil
	})
}
pulumi {
  required_providers {
    aws = {
      source = "pulumi/aws"
    }
  }
}

resource "aws_ec2_networkinterface" "example" {
  attachments {
    instance     = exampleAwsInstance.id
    device_index = 1
  }
  subnet_id       = exampleAwsSubnet.id
  private_ips     = ["10.0.0.50"]
  security_groups = [exampleAwsSecurityGroup.id]
}
resource "aws_ec2_networkinterfacepermission" "example" {
  network_interface_id = aws_ec2_networkinterface.example.id
  aws_account_id       = "123456789012"
  permission           = "INSTANCE-ATTACH"
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.ec2.NetworkInterface;
import com.pulumi.aws.ec2.NetworkInterfaceArgs;
import com.pulumi.aws.ec2.inputs.NetworkInterfaceAttachmentArgs;
import com.pulumi.aws.ec2.NetworkInterfacePermission;
import com.pulumi.aws.ec2.NetworkInterfacePermissionArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        var example = new NetworkInterface("example", NetworkInterfaceArgs.builder()
            .attachments(NetworkInterfaceAttachmentArgs.builder()
                .instance(exampleAwsInstance.id())
                .deviceIndex(1)
                .build())
            .subnetId(exampleAwsSubnet.id())
            .privateIps("10.0.0.50")
            .securityGroups(exampleAwsSecurityGroup.id())
            .build());

        var exampleNetworkInterfacePermission = new NetworkInterfacePermission("exampleNetworkInterfacePermission", NetworkInterfacePermissionArgs.builder()
            .networkInterfaceId(example.id())
            .awsAccountId("123456789012")
            .permission("INSTANCE-ATTACH")
            .build());

    }
}
resources:
  example:
    type: aws:ec2:NetworkInterface
    properties:
      attachments:
        - instance: ${exampleAwsInstance.id}
          deviceIndex: 1
      subnetId: ${exampleAwsSubnet.id}
      privateIps:
        - 10.0.0.50
      securityGroups:
        - ${exampleAwsSecurityGroup.id}
  exampleNetworkInterfacePermission:
    type: aws:ec2:NetworkInterfacePermission
    name: example
    properties:
      networkInterfaceId: ${example.id}
      awsAccountId: '123456789012'
      permission: INSTANCE-ATTACH

Import

Using pulumi import, import Network Interface Permissions using the networkInterfacePermissionId. For example:

$ pulumi import aws:ec2/networkInterfacePermission:NetworkInterfacePermission example eni-perm-056ad97ce2ac377ed

Constructors

NetworkInterfacePermission(String name, {NetworkInterfacePermissionArgs? args, CustomResourceOptions? options})
Creates a new NetworkInterfacePermission. name The Pulumi resource name. args Arguments used to configure this NetworkInterfacePermission. The set of arguments for NetworkInterfacePermission. options Resource options controlling this resource's behavior.
NetworkInterfacePermission.reference(String urn)
Creates a typed reference to an existing NetworkInterfacePermission resource.

Properties

awsAccountId ↔ Output<String>
The Amazon Web Services account ID.
latefinal
childResources → Set<Resource>
finalinherited
completionSources ↔ Map<String, IOutputCompletionSource>
latefinalinherited
hashCode → int
The hash code for this object.
no setterinherited
id ↔ Output<String>
getter/setter pairinherited
isCustom → bool
Returns whether this resource is provider-managed.
no setterinherited
isProtected → bool
Returns whether this resource is protected from deletion.
no setterinherited
isRemote → bool
Whether this resource is registered as remote.
no setterinherited
isResourceReference → bool
Whether this instance represents a resource value returned over RPC.
finalinherited
networkInterfaceId ↔ Output<String>
The ID of the network interface.
latefinal
networkInterfacePermissionId ↔ Output<String>
ENI permission ID.
latefinal
permission ↔ Output<String>
The type of permission to grant. Valid values are INSTANCE-ATTACH or EIP-ASSOCIATE.
latefinal
region ↔ Output<String>
Region where this resource will be managed. Defaults to the Region set in the provider configuration.
latefinal
resourceTransforms → List<ResourceTransform>
Inherited/explicit async transforms.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
timeouts ↔ Output<NetworkInterfacePermissionTimeouts?>
latefinal
transformations → List<ResourceTransformation>
Inherited/explicit legacy transformations.
no setterinherited
urn ↔ Output<String>
latefinalinherited

Methods

failId(Object error) → void
Completes this resource ID with an error when registration fails.
inherited
failOutputs(Object error) → void
Completes all output properties with error.
inherited
failUrn(Object error) → void
Completes this resource URN with an error when registration fails.
inherited
getProvider(String moduleMember) → ProviderResource?
Returns provider for moduleMember's package, if configured.
inherited
getResourceName() → String
Returns this resource's logical name.
inherited
getResourceType() → String
Returns this resource's Pulumi type token.
inherited
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
registerOutput<T>(String propertyName, {Object? decoder(Object?)?, bool isSecret = false}) → Output<T>
Registers a dynamic output property for this resource.
inherited
resolveId(String? value, {required bool isKnown}) → void
Resolves the provider-assigned ID for this resource.
inherited
resolveOutputs(Struct outputs) → void
Resolves all output properties from a monitor response payload.
inherited
resolveUrn(String value) → void
Resolves this resource's URN once assigned by the engine.
inherited
serializeProperties(Map<String, dynamic> properties) → Future<Struct>
Serializes resource properties for RPC transmission.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

get(String name, Input<String> id, {NetworkInterfacePermissionState? state, CustomResourceOptions? options}) → NetworkInterfacePermission
Gets an existing NetworkInterfacePermission resource's state with the given name and id.