getCoreNetworkPolicyDocument function

Future<GetCoreNetworkPolicyDocumentResult> getCoreNetworkPolicyDocument(
  1. GetCoreNetworkPolicyDocumentArgs args, {
  2. InvokeOptions? options,
})

Generates a Core Network policy document in JSON format for use with resources that expect core network policy documents such as awsccNetworkmanagerCoreNetwork. It follows the API definition from the core-network-policy documentation.

Using this data source to generate policy documents is optional. It is also valid to use literal JSON strings in your configuration or to use the file interpolation function to read a raw JSON policy document from a file.

Example Usage

Basic Example

import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";

const test = aws.networkmanager.getCoreNetworkPolicyDocument({
    attachmentPolicies: [
        {
            action: {
                associationMethod: "constant",
                segment: "shared",
            },
            conditions: [{
                type: "tag-value",
                operator: "equals",
                key: "segment",
                value: "shared",
            }],
            ruleNumber: 100,
            conditionLogic: "or",
        },
        {
            action: {
                associationMethod: "constant",
                segment: "prod",
            },
            conditions: [{
                type: "tag-value",
                operator: "equals",
                key: "segment",
                value: "prod",
            }],
            ruleNumber: 200,
            conditionLogic: "or",
        },
    ],
    coreNetworkConfigurations: [{
        edgeLocations: [
            {
                location: "us-east-1",
                asn: "64512",
            },
            {
                location: "eu-central-1",
                asn: "64513",
            },
        ],
        vpnEcmpSupport: false,
        asnRanges: ["64512-64555"],
    }],
    segmentActions: [{
        action: "share",
        mode: "attachment-route",
        segment: "shared",
        shareWiths: ["*"],
    }],
    segments: [
        {
            name: "shared",
            description: "Segment for shared services",
            requireAttachmentAcceptance: true,
        },
        {
            name: "prod",
            description: "Segment for prod services",
            requireAttachmentAcceptance: true,
        },
    ],
});
import pulumi
import pulumi_aws as aws

test = aws.networkmanager.get_core_network_policy_document(attachment_policies=[
        {
            "action": {
                "association_method": "constant",
                "segment": "shared",
            },
            "conditions": [{
                "type": "tag-value",
                "operator": "equals",
                "key": "segment",
                "value": "shared",
            }],
            "rule_number": 100,
            "condition_logic": "or",
        },
        {
            "action": {
                "association_method": "constant",
                "segment": "prod",
            },
            "conditions": [{
                "type": "tag-value",
                "operator": "equals",
                "key": "segment",
                "value": "prod",
            }],
            "rule_number": 200,
            "condition_logic": "or",
        },
    ],
    core_network_configurations=[{
        "edge_locations": [
            {
                "location": "us-east-1",
                "asn": "64512",
            },
            {
                "location": "eu-central-1",
                "asn": "64513",
            },
        ],
        "vpn_ecmp_support": False,
        "asn_ranges": ["64512-64555"],
    }],
    segment_actions=[{
        "action": "share",
        "mode": "attachment-route",
        "segment": "shared",
        "share_withs": ["*"],
    }],
    segments=[
        {
            "name": "shared",
            "description": "Segment for shared services",
            "require_attachment_acceptance": True,
        },
        {
            "name": "prod",
            "description": "Segment for prod services",
            "require_attachment_acceptance": True,
        },
    ])
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;

return await Deployment.RunAsync(() =>
{
    var test = Aws.NetworkManager.GetCoreNetworkPolicyDocument.Invoke(new()
    {
        AttachmentPolicies = new[]
        {
            new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyInputArgs
            {
                Action = new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyActionInputArgs
                {
                    AssociationMethod = "constant",
                    Segment = "shared",
                },
                Conditions = new[]
                {
                    new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyConditionInputArgs
                    {
                        Type = "tag-value",
                        Operator = "equals",
                        Key = "segment",
                        Value = "shared",
                    },
                },
                RuleNumber = 100,
                ConditionLogic = "or",
            },
            new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyInputArgs
            {
                Action = new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyActionInputArgs
                {
                    AssociationMethod = "constant",
                    Segment = "prod",
                },
                Conditions = new[]
                {
                    new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyConditionInputArgs
                    {
                        Type = "tag-value",
                        Operator = "equals",
                        Key = "segment",
                        Value = "prod",
                    },
                },
                RuleNumber = 200,
                ConditionLogic = "or",
            },
        },
        CoreNetworkConfigurations = new[]
        {
            new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentCoreNetworkConfigurationInputArgs
            {
                EdgeLocations = new[]
                {
                    new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentCoreNetworkConfigurationEdgeLocationInputArgs
                    {
                        Location = "us-east-1",
                        Asn = "64512",
                    },
                    new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentCoreNetworkConfigurationEdgeLocationInputArgs
                    {
                        Location = "eu-central-1",
                        Asn = "64513",
                    },
                },
                VpnEcmpSupport = false,
                AsnRanges = new[]
                {
                    "64512-64555",
                },
            },
        },
        SegmentActions = new[]
        {
            new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentSegmentActionInputArgs
            {
                Action = "share",
                Mode = "attachment-route",
                Segment = "shared",
                ShareWiths = new[]
                {
                    "*",
                },
            },
        },
        Segments = new[]
        {
            new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentSegmentInputArgs
            {
                Name = "shared",
                Description = "Segment for shared services",
                RequireAttachmentAcceptance = true,
            },
            new Aws.NetworkManager.Inputs.GetCoreNetworkPolicyDocumentSegmentInputArgs
            {
                Name = "prod",
                Description = "Segment for prod services",
                RequireAttachmentAcceptance = true,
            },
        },
    });

});
package main

import (
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/networkmanager"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		_, err := networkmanager.GetCoreNetworkPolicyDocument(ctx, &networkmanager.GetCoreNetworkPolicyDocumentArgs{
			AttachmentPolicies: []networkmanager.GetCoreNetworkPolicyDocumentAttachmentPolicy{
				{
					Action: {
						AssociationMethod: pulumi.StringRef("constant"),
						Segment:           pulumi.StringRef("shared"),
					},
					Conditions: []networkmanager.GetCoreNetworkPolicyDocumentAttachmentPolicyCondition{
						{
							Type:     "tag-value",
							Operator: pulumi.StringRef("equals"),
							Key:      pulumi.StringRef("segment"),
							Value:    pulumi.StringRef("shared"),
						},
					},
					RuleNumber:     100,
					ConditionLogic: pulumi.StringRef("or"),
				},
				{
					Action: {
						AssociationMethod: pulumi.StringRef("constant"),
						Segment:           pulumi.StringRef("prod"),
					},
					Conditions: []networkmanager.GetCoreNetworkPolicyDocumentAttachmentPolicyCondition{
						{
							Type:     "tag-value",
							Operator: pulumi.StringRef("equals"),
							Key:      pulumi.StringRef("segment"),
							Value:    pulumi.StringRef("prod"),
						},
					},
					RuleNumber:     200,
					ConditionLogic: pulumi.StringRef("or"),
				},
			},
			CoreNetworkConfigurations: []networkmanager.GetCoreNetworkPolicyDocumentCoreNetworkConfiguration{
				{
					EdgeLocations: []networkmanager.GetCoreNetworkPolicyDocumentCoreNetworkConfigurationEdgeLocation{
						{
							Location: "us-east-1",
							Asn:      pulumi.StringRef("64512"),
						},
						{
							Location: "eu-central-1",
							Asn:      pulumi.StringRef("64513"),
						},
					},
					VpnEcmpSupport: pulumi.BoolRef(false),
					AsnRanges: []string{
						"64512-64555",
					},
				},
			},
			SegmentActions: []networkmanager.GetCoreNetworkPolicyDocumentSegmentAction{
				{
					Action:  "share",
					Mode:    pulumi.StringRef("attachment-route"),
					Segment: "shared",
					ShareWiths: []string{
						"*",
					},
				},
			},
			Segments: []networkmanager.GetCoreNetworkPolicyDocumentSegment{
				{
					Name:                        "shared",
					Description:                 pulumi.StringRef("Segment for shared services"),
					RequireAttachmentAcceptance: pulumi.BoolRef(true),
				},
				{
					Name:                        "prod",
					Description:                 pulumi.StringRef("Segment for prod services"),
					RequireAttachmentAcceptance: pulumi.BoolRef(true),
				},
			},
		}, nil)
		if err != nil {
			return err
		}
		return nil
	})
}
pulumi {
  required_providers {
    aws = {
      source = "pulumi/aws"
    }
  }
}

data "aws_networkmanager_getcorenetworkpolicydocument" "test" {
  attachment_policies {
    action = {
      association_method = "constant"
      segment            = "shared"
    }
    conditions {
      type     = "tag-value"
      operator = "equals"
      key      = "segment"
      value    = "shared"
    }
    rule_number     = 100
    condition_logic = "or"
  }
  attachment_policies {
    action = {
      association_method = "constant"
      segment            = "prod"
    }
    conditions {
      type     = "tag-value"
      operator = "equals"
      key      = "segment"
      value    = "prod"
    }
    rule_number     = 200
    condition_logic = "or"
  }
  core_network_configurations {
    edge_locations {
      location = "us-east-1"
      asn      = 64512
    }
    edge_locations {
      location = "eu-central-1"
      asn      = 64513
    }
    vpn_ecmp_support = false
    asn_ranges       = ["64512-64555"]
  }
  segment_actions {
    action      = "share"
    mode        = "attachment-route"
    segment     = "shared"
    share_withs = ["*"]
  }
  segments {
    name                          = "shared"
    description                   = "Segment for shared services"
    require_attachment_acceptance = true
  }
  segments {
    name                          = "prod"
    description                   = "Segment for prod services"
    require_attachment_acceptance = true
  }
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.networkmanager.NetworkmanagerFunctions;
import com.pulumi.aws.networkmanager.inputs.GetCoreNetworkPolicyDocumentArgs;
import com.pulumi.aws.networkmanager.inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyArgs;
import com.pulumi.aws.networkmanager.inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyActionArgs;
import com.pulumi.aws.networkmanager.inputs.GetCoreNetworkPolicyDocumentAttachmentPolicyConditionArgs;
import com.pulumi.aws.networkmanager.inputs.GetCoreNetworkPolicyDocumentCoreNetworkConfigurationArgs;
import com.pulumi.aws.networkmanager.inputs.GetCoreNetworkPolicyDocumentCoreNetworkConfigurationEdgeLocationArgs;
import com.pulumi.aws.networkmanager.inputs.GetCoreNetworkPolicyDocumentSegmentActionArgs;
import com.pulumi.aws.networkmanager.inputs.GetCoreNetworkPolicyDocumentSegmentArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        final var test = NetworkmanagerFunctions.getCoreNetworkPolicyDocument(GetCoreNetworkPolicyDocumentArgs.builder()
            .attachmentPolicies(
                GetCoreNetworkPolicyDocumentAttachmentPolicyArgs.builder()
                    .action(GetCoreNetworkPolicyDocumentAttachmentPolicyActionArgs.builder()
                        .associationMethod("constant")
                        .segment("shared")
                        .build())
                    .conditions(GetCoreNetworkPolicyDocumentAttachmentPolicyConditionArgs.builder()
                        .type("tag-value")
                        .operator("equals")
                        .key("segment")
                        .value("shared")
                        .build())
                    .ruleNumber(100)
                    .conditionLogic("or")
                    .build(),
                GetCoreNetworkPolicyDocumentAttachmentPolicyArgs.builder()
                    .action(GetCoreNetworkPolicyDocumentAttachmentPolicyActionArgs.builder()
                        .associationMethod("constant")
                        .segment("prod")
                        .build())
                    .conditions(GetCoreNetworkPolicyDocumentAttachmentPolicyConditionArgs.builder()
                        .type("tag-value")
                        .operator("equals")
                        .key("segment")
                        .value("prod")
                        .build())
                    .ruleNumber(200)
                    .conditionLogic("or")
                    .build())
            .coreNetworkConfigurations(GetCoreNetworkPolicyDocumentCoreNetworkConfigurationArgs.builder()
                .edgeLocations(
                    GetCoreNetworkPolicyDocumentCoreNetworkConfigurationEdgeLocationArgs.builder()
                        .location("us-east-1")
                        .asn("64512")
                        .build(),
                    GetCoreNetworkPolicyDocumentCoreNetworkConfigurationEdgeLocationArgs.builder()
                        .location("eu-central-1")
                        .asn("64513")
                        .build())
                .vpnEcmpSupport(false)
                .asnRanges("64512-64555")
                .build())
            .segmentActions(GetCoreNetworkPolicyDocumentSegmentActionArgs.builder()
                .action("share")
                .mode("attachment-route")
                .segment("shared")
                .shareWiths("*")
                .build())
            .segments(
                GetCoreNetworkPolicyDocumentSegmentArgs.builder()
                    .name("shared")
                    .description("Segment for shared services")
                    .requireAttachmentAcceptance(true)
                    .build(),
                GetCoreNetworkPolicyDocumentSegmentArgs.builder()
                    .name("prod")
                    .description("Segment for prod services")
                    .requireAttachmentAcceptance(true)
                    .build())
            .build());

    }
}
variables:
  test:
    fn::invoke:
      function: aws:networkmanager:getCoreNetworkPolicyDocument
      arguments:
        attachmentPolicies:
          - action:
              associationMethod: constant
              segment: shared
            conditions:
              - type: tag-value
                operator: equals
                key: segment
                value: shared
            ruleNumber: 100
            conditionLogic: or
          - action:
              associationMethod: constant
              segment: prod
            conditions:
              - type: tag-value
                operator: equals
                key: segment
                value: prod
            ruleNumber: 200
            conditionLogic: or
        coreNetworkConfigurations:
          - edgeLocations:
              - location: us-east-1
                asn: 64512
              - location: eu-central-1
                asn: 64513
            vpnEcmpSupport: false
            asnRanges:
              - 64512-64555
        segmentActions:
          - action: share
            mode: attachment-route
            segment: shared
            shareWiths:
              - '*'
        segments:
          - name: shared
            description: Segment for shared services
            requireAttachmentAcceptance: true
          - name: prod
            description: Segment for prod services
            requireAttachmentAcceptance: true

data.aws_networkmanager_core_network_policy_document.test.json will evaluate to:

{
  "version": "2021.12",
  "core-network-configuration": {
    "asn-ranges": [
      "64512-64555"
    ],
    "vpn-ecmp-support": false,
    "edge-locations": [
      {
        "location": "us-east-1",
        "asn": 64512
      },
      {
        "location": "eu-central-1",
        "asn": 64513
      }
    ]
  },
  "segments": [
    {
      "name": "shared",
      "description": "Segment for shared services",
      "require-attachment-acceptance": true
    },
    {
      "name": "prod",
      "description": "Segment for prod services",
      "require-attachment-acceptance": true
    }
  ],
  "attachment-policies": [
    {
      "rule-number": 100,
      "action": {
        "association-method": "constant",
        "segment": "shared"
      },
      "conditions": [
        {
          "type": "tag-value",
          "operator": "equals",
          "key": "segment",
          "value": "shared"
        }
      ],
      "condition-logic": "or"
    },
    {
      "rule-number": 200,
      "action": {
        "association-method": "constant",
        "segment": "prod"
      },
      "conditions": [
        {
          "type": "tag-value",
          "operator": "equals",
          "key": "segment",
          "value": "prod"
        }
      ],
      "condition-logic": "or"
    }
  ],
  "segment-actions": [
    {
      "action": "share",
      "mode": "attachment-route",
      "segment": "shared",
      "share-with": "*"
    }
  ]
}

args Arguments passed to this invoke. Arguments for getCoreNetworkPolicyDocument. options Invoke options controlling this call.

Implementation

Future<GetCoreNetworkPolicyDocumentResult> getCoreNetworkPolicyDocument(
  GetCoreNetworkPolicyDocumentArgs args, {
  pulumi.InvokeOptions? options,
}) async {
  final deployment = pulumi.Deployment.instance;
  final result = await deployment.invoke<Map<String, dynamic>>(
    'aws:networkmanager/getCoreNetworkPolicyDocument:getCoreNetworkPolicyDocument',
    args.toMap(),
    options: pulumi.toDeploymentInvokeOptions(options),
  );
  return GetCoreNetworkPolicyDocumentResult.fromMap(result);
}