IdentityProvider class

Resource for managing an AWS WorkSpaces Web Identity Provider.

Example Usage

Basic Usage with SAML

import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";

const example = new aws.workspacesweb.Portal("example", {displayName: "example"});
const exampleIdentityProvider = new aws.workspacesweb.IdentityProvider("example", {
    identityProviderName: "example-saml",
    identityProviderType: "SAML",
    portalArn: example.portalArn,
    identityProviderDetails: {
        MetadataURL: "https://example.com/metadata",
    },
});
import pulumi
import pulumi_aws as aws

example = aws.workspacesweb.Portal("example", display_name="example")
example_identity_provider = aws.workspacesweb.IdentityProvider("example",
    identity_provider_name="example-saml",
    identity_provider_type="SAML",
    portal_arn=example.portal_arn,
    identity_provider_details={
        "MetadataURL": "https://example.com/metadata",
    })
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;

return await Deployment.RunAsync(() =>
{
    var example = new Aws.WorkSpacesWeb.Portal("example", new()
    {
        DisplayName = "example",
    });

    var exampleIdentityProvider = new Aws.WorkSpacesWeb.IdentityProvider("example", new()
    {
        IdentityProviderName = "example-saml",
        IdentityProviderType = "SAML",
        PortalArn = example.PortalArn,
        IdentityProviderDetails =
        {
            { "MetadataURL", "https://example.com/metadata" },
        },
    });

});
package main

import (
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/workspacesweb"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		example, err := workspacesweb.NewPortal(ctx, "example", &workspacesweb.PortalArgs{
			DisplayName: pulumi.String("example"),
		})
		if err != nil {
			return err
		}
		_, err = workspacesweb.NewIdentityProvider(ctx, "example", &workspacesweb.IdentityProviderArgs{
			IdentityProviderName: pulumi.String("example-saml"),
			IdentityProviderType: pulumi.String("SAML"),
			PortalArn:            example.PortalArn,
			IdentityProviderDetails: pulumi.StringMap{
				"MetadataURL": pulumi.String("https://example.com/metadata"),
			},
		})
		if err != nil {
			return err
		}
		return nil
	})
}
pulumi {
  required_providers {
    aws = {
      source = "pulumi/aws"
    }
  }
}

resource "aws_workspacesweb_portal" "example" {
  display_name = "example"
}
resource "aws_workspacesweb_identityprovider" "example" {
  identity_provider_name = "example-saml"
  identity_provider_type = "SAML"
  portal_arn             = aws_workspacesweb_portal.example.portal_arn
  identity_provider_details = {
    "MetadataURL" = "https://example.com/metadata"
  }
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.workspacesweb.Portal;
import com.pulumi.aws.workspacesweb.PortalArgs;
import com.pulumi.aws.workspacesweb.IdentityProvider;
import com.pulumi.aws.workspacesweb.IdentityProviderArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        var example = new Portal("example", PortalArgs.builder()
            .displayName("example")
            .build());

        var exampleIdentityProvider = new IdentityProvider("exampleIdentityProvider", IdentityProviderArgs.builder()
            .identityProviderName("example-saml")
            .identityProviderType("SAML")
            .portalArn(example.portalArn())
            .identityProviderDetails(Map.of("MetadataURL", "https://example.com/metadata"))
            .build());

    }
}
resources:
  example:
    type: aws:workspacesweb:Portal
    properties:
      displayName: example
  exampleIdentityProvider:
    type: aws:workspacesweb:IdentityProvider
    name: example
    properties:
      identityProviderName: example-saml
      identityProviderType: SAML
      portalArn: ${example.portalArn}
      identityProviderDetails:
        MetadataURL: https://example.com/metadata

OIDC Identity Provider

import * as pulumi from "@pulumi/pulumi";
import * as aws from "@pulumi/aws";

const test = new aws.workspacesweb.Portal("test", {displayName: "test"});
const testIdentityProvider = new aws.workspacesweb.IdentityProvider("test", {
    identityProviderName: "test-updated",
    identityProviderType: "OIDC",
    portalArn: test.portalArn,
    identityProviderDetails: {
        client_id: "test-client-id",
        client_secret: "test-client-secret",
        oidc_issuer: "https://accounts.google.com",
        attributes_request_method: "POST",
        authorize_scopes: "openid, email",
    },
});
import pulumi
import pulumi_aws as aws

test = aws.workspacesweb.Portal("test", display_name="test")
test_identity_provider = aws.workspacesweb.IdentityProvider("test",
    identity_provider_name="test-updated",
    identity_provider_type="OIDC",
    portal_arn=test.portal_arn,
    identity_provider_details={
        "client_id": "test-client-id",
        "client_secret": "test-client-secret",
        "oidc_issuer": "https://accounts.google.com",
        "attributes_request_method": "POST",
        "authorize_scopes": "openid, email",
    })
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Aws = Pulumi.Aws;

return await Deployment.RunAsync(() =>
{
    var test = new Aws.WorkSpacesWeb.Portal("test", new()
    {
        DisplayName = "test",
    });

    var testIdentityProvider = new Aws.WorkSpacesWeb.IdentityProvider("test", new()
    {
        IdentityProviderName = "test-updated",
        IdentityProviderType = "OIDC",
        PortalArn = test.PortalArn,
        IdentityProviderDetails =
        {
            { "client_id", "test-client-id" },
            { "client_secret", "test-client-secret" },
            { "oidc_issuer", "https://accounts.google.com" },
            { "attributes_request_method", "POST" },
            { "authorize_scopes", "openid, email" },
        },
    });

});
package main

import (
	"github.com/pulumi/pulumi-aws/sdk/v7/go/aws/workspacesweb"
	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)

func main() {
	pulumi.Run(func(ctx *pulumi.Context) error {
		test, err := workspacesweb.NewPortal(ctx, "test", &workspacesweb.PortalArgs{
			DisplayName: pulumi.String("test"),
		})
		if err != nil {
			return err
		}
		_, err = workspacesweb.NewIdentityProvider(ctx, "test", &workspacesweb.IdentityProviderArgs{
			IdentityProviderName: pulumi.String("test-updated"),
			IdentityProviderType: pulumi.String("OIDC"),
			PortalArn:            test.PortalArn,
			IdentityProviderDetails: pulumi.StringMap{
				"client_id":                 pulumi.String("test-client-id"),
				"client_secret":             pulumi.String("test-client-secret"),
				"oidc_issuer":               pulumi.String("https://accounts.google.com"),
				"attributes_request_method": pulumi.String("POST"),
				"authorize_scopes":          pulumi.String("openid, email"),
			},
		})
		if err != nil {
			return err
		}
		return nil
	})
}
pulumi {
  required_providers {
    aws = {
      source = "pulumi/aws"
    }
  }
}

resource "aws_workspacesweb_portal" "test" {
  display_name = "test"
}
resource "aws_workspacesweb_identityprovider" "test" {
  identity_provider_name = "test-updated"
  identity_provider_type = "OIDC"
  portal_arn             = aws_workspacesweb_portal.test.portal_arn
  identity_provider_details = {
    "client_id"                 = "test-client-id"
    "client_secret"             = "test-client-secret"
    "oidc_issuer"               = "https://accounts.google.com"
    "attributes_request_method" = "POST"
    "authorize_scopes"          = "openid, email"
  }
}
package generated_program;

import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.aws.workspacesweb.Portal;
import com.pulumi.aws.workspacesweb.PortalArgs;
import com.pulumi.aws.workspacesweb.IdentityProvider;
import com.pulumi.aws.workspacesweb.IdentityProviderArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;

public class App {
    public static void main(String[] args) {
        Pulumi.run(App::stack);
    }

    public static void stack(Context ctx) {
        var test = new Portal("test", PortalArgs.builder()
            .displayName("test")
            .build());

        var testIdentityProvider = new IdentityProvider("testIdentityProvider", IdentityProviderArgs.builder()
            .identityProviderName("test-updated")
            .identityProviderType("OIDC")
            .portalArn(test.portalArn())
            .identityProviderDetails(Map.ofEntries(
                Map.entry("client_id", "test-client-id"),
                Map.entry("client_secret", "test-client-secret"),
                Map.entry("oidc_issuer", "https://accounts.google.com"),
                Map.entry("attributes_request_method", "POST"),
                Map.entry("authorize_scopes", "openid, email")
            ))
            .build());

    }
}
resources:
  test:
    type: aws:workspacesweb:Portal
    properties:
      displayName: test
  testIdentityProvider:
    type: aws:workspacesweb:IdentityProvider
    name: test
    properties:
      identityProviderName: test-updated
      identityProviderType: OIDC
      portalArn: ${test.portalArn}
      identityProviderDetails:
        client_id: test-client-id
        client_secret: test-client-secret
        oidc_issuer: https://accounts.google.com
        attributes_request_method: POST
        authorize_scopes: openid, email

Import

Using pulumi import, import WorkSpaces Web Identity Provider using the identityProviderArn. For example:

$ pulumi import aws:workspacesweb/identityProvider:IdentityProvider example arn:aws:workspaces-web:us-west-2:123456789012:identityprovider/abcdef12345678/12345678-1234-1234-1234-123456789012

Constructors

IdentityProvider(String name, {IdentityProviderArgs? args, CustomResourceOptions? options})
Creates a new IdentityProvider. name The Pulumi resource name. args Arguments used to configure this IdentityProvider. The set of arguments for IdentityProvider. options Resource options controlling this resource's behavior.
IdentityProvider.reference(String urn)
Creates a typed reference to an existing IdentityProvider resource.

Properties

childResources → Set<Resource>
finalinherited
completionSources ↔ Map<String, IOutputCompletionSource>
latefinalinherited
hashCode → int
The hash code for this object.
no setterinherited
id ↔ Output<String>
getter/setter pairinherited
identityProviderArn ↔ Output<String>
ARN of the identity provider.
latefinal
identityProviderDetails ↔ Output<Map<String, String>>
Identity provider details. The following list describes the provider detail keys for each identity provider type:
latefinal
identityProviderName ↔ Output<String>
Identity provider name.
latefinal
identityProviderType ↔ Output<String>
Identity provider type. Valid values: SAML, Facebook, Google, LoginWithAmazon, SignInWithApple, OIDC.
latefinal
isCustom → bool
Returns whether this resource is provider-managed.
no setterinherited
isProtected → bool
Returns whether this resource is protected from deletion.
no setterinherited
isRemote → bool
Whether this resource is registered as remote.
no setterinherited
isResourceReference → bool
Whether this instance represents a resource value returned over RPC.
finalinherited
portalArn ↔ Output<String>
ARN of the web portal. Forces replacement if changed.
latefinal
region ↔ Output<String>
Region where this resource will be managed. Defaults to the Region set in the provider configuration.
latefinal
resourceTransforms → List<ResourceTransform>
Inherited/explicit async transforms.
no setterinherited
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
tags ↔ Output<Map<String, String>?>
Map of tags to assign to the resource. If configured with a provider defaultTags configuration block present, tags with matching keys will overwrite those defined at the provider-level.
latefinal
tagsAll ↔ Output<Map<String, String>>
Map of tags assigned to the resource, including those inherited from the provider defaultTags configuration block.
latefinal
transformations → List<ResourceTransformation>
Inherited/explicit legacy transformations.
no setterinherited
urn ↔ Output<String>
latefinalinherited

Methods

failId(Object error) → void
Completes this resource ID with an error when registration fails.
inherited
failOutputs(Object error) → void
Completes all output properties with error.
inherited
failUrn(Object error) → void
Completes this resource URN with an error when registration fails.
inherited
getProvider(String moduleMember) → ProviderResource?
Returns provider for moduleMember's package, if configured.
inherited
getResourceName() → String
Returns this resource's logical name.
inherited
getResourceType() → String
Returns this resource's Pulumi type token.
inherited
noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
registerOutput<T>(String propertyName, {Object? decoder(Object?)?, bool isSecret = false}) → Output<T>
Registers a dynamic output property for this resource.
inherited
resolveId(String? value, {required bool isKnown}) → void
Resolves the provider-assigned ID for this resource.
inherited
resolveOutputs(Struct outputs) → void
Resolves all output properties from a monitor response payload.
inherited
resolveUrn(String value) → void
Resolves this resource's URN once assigned by the engine.
inherited
serializeProperties(Map<String, dynamic> properties) → Future<Struct>
Serializes resource properties for RPC transmission.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Static Methods

get(String name, Input<String> id, {IdentityProviderState? state, CustomResourceOptions? options}) → IdentityProvider
Gets an existing IdentityProvider resource's state with the given name and id.