com.pulumi.aws.securityhub.ConfigurationPolicy Maven / Gradle / Ivy
Go to download
Show more of this group Show more artifacts with this name
Show all versions of aws Show documentation
Show all versions of aws Show documentation
A Pulumi package for creating and managing Amazon Web Services (AWS) cloud resources.
// *** WARNING: this file was generated by pulumi-java-gen. ***
// *** Do not edit by hand unless you're certain you know what you are doing! ***
package com.pulumi.aws.securityhub;
import com.pulumi.aws.Utilities;
import com.pulumi.aws.securityhub.ConfigurationPolicyArgs;
import com.pulumi.aws.securityhub.inputs.ConfigurationPolicyState;
import com.pulumi.aws.securityhub.outputs.ConfigurationPolicyConfigurationPolicy;
import com.pulumi.core.Output;
import com.pulumi.core.annotations.Export;
import com.pulumi.core.annotations.ResourceType;
import com.pulumi.core.internal.Codegen;
import java.lang.String;
import java.util.Optional;
import javax.annotation.Nullable;
/**
* Manages Security Hub configuration policy
*
* > **NOTE:** This resource requires `aws.securityhub.OrganizationConfiguration` to be configured of type `CENTRAL`. More information about Security Hub central configuration and configuration policies can be found in the [How Security Hub configuration policies work](https://docs.aws.amazon.com/securityhub/latest/userguide/configuration-policies-overview.html) documentation.
*
* ## Example Usage
*
* ### Default standards enabled
*
* <!--Start PulumiCodeChooser -->
*
* {@code
* package generated_program;
*
* import com.pulumi.Context;
* import com.pulumi.Pulumi;
* import com.pulumi.core.Output;
* import com.pulumi.aws.securityhub.FindingAggregator;
* import com.pulumi.aws.securityhub.FindingAggregatorArgs;
* import com.pulumi.aws.securityhub.OrganizationConfiguration;
* import com.pulumi.aws.securityhub.OrganizationConfigurationArgs;
* import com.pulumi.aws.securityhub.inputs.OrganizationConfigurationOrganizationConfigurationArgs;
* import com.pulumi.aws.securityhub.ConfigurationPolicy;
* import com.pulumi.aws.securityhub.ConfigurationPolicyArgs;
* import com.pulumi.aws.securityhub.inputs.ConfigurationPolicyConfigurationPolicyArgs;
* import com.pulumi.aws.securityhub.inputs.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationArgs;
* import com.pulumi.resources.CustomResourceOptions;
* import java.util.List;
* import java.util.ArrayList;
* import java.util.Map;
* import java.io.File;
* import java.nio.file.Files;
* import java.nio.file.Paths;
*
* public class App {
* public static void main(String[] args) {
* Pulumi.run(App::stack);
* }
*
* public static void stack(Context ctx) {
* var example = new FindingAggregator("example", FindingAggregatorArgs.builder()
* .linkingMode("ALL_REGIONS")
* .build());
*
* var exampleOrganizationConfiguration = new OrganizationConfiguration("exampleOrganizationConfiguration", OrganizationConfigurationArgs.builder()
* .autoEnable(false)
* .autoEnableStandards("NONE")
* .organizationConfiguration(OrganizationConfigurationOrganizationConfigurationArgs.builder()
* .configurationType("CENTRAL")
* .build())
* .build(), CustomResourceOptions.builder()
* .dependsOn(example)
* .build());
*
* var exampleConfigurationPolicy = new ConfigurationPolicy("exampleConfigurationPolicy", ConfigurationPolicyArgs.builder()
* .name("Example")
* .description("This is an example configuration policy")
* .configurationPolicy(ConfigurationPolicyConfigurationPolicyArgs.builder()
* .serviceEnabled(true)
* .enabledStandardArns(
* "arn:aws:securityhub:us-east-1::standards/aws-foundational-security-best-practices/v/1.0.0",
* "arn:aws:securityhub:::ruleset/cis-aws-foundations-benchmark/v/1.2.0")
* .securityControlsConfiguration(ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationArgs.builder()
* .disabledControlIdentifiers()
* .build())
* .build())
* .build(), CustomResourceOptions.builder()
* .dependsOn(exampleOrganizationConfiguration)
* .build());
*
* }
* }
* }
*
* <!--End PulumiCodeChooser -->
*
* ### Disabled Policy
*
* <!--Start PulumiCodeChooser -->
*
* {@code
* package generated_program;
*
* import com.pulumi.Context;
* import com.pulumi.Pulumi;
* import com.pulumi.core.Output;
* import com.pulumi.aws.securityhub.ConfigurationPolicy;
* import com.pulumi.aws.securityhub.ConfigurationPolicyArgs;
* import com.pulumi.aws.securityhub.inputs.ConfigurationPolicyConfigurationPolicyArgs;
* import com.pulumi.resources.CustomResourceOptions;
* import java.util.List;
* import java.util.ArrayList;
* import java.util.Map;
* import java.io.File;
* import java.nio.file.Files;
* import java.nio.file.Paths;
*
* public class App {
* public static void main(String[] args) {
* Pulumi.run(App::stack);
* }
*
* public static void stack(Context ctx) {
* var disabled = new ConfigurationPolicy("disabled", ConfigurationPolicyArgs.builder()
* .name("Disabled")
* .description("This is an example of disabled configuration policy")
* .configurationPolicy(ConfigurationPolicyConfigurationPolicyArgs.builder()
* .serviceEnabled(false)
* .build())
* .build(), CustomResourceOptions.builder()
* .dependsOn(example)
* .build());
*
* }
* }
* }
*
* <!--End PulumiCodeChooser -->
*
* ### Custom Control Configuration
*
* <!--Start PulumiCodeChooser -->
*
* {@code
* package generated_program;
*
* import com.pulumi.Context;
* import com.pulumi.Pulumi;
* import com.pulumi.core.Output;
* import com.pulumi.aws.securityhub.ConfigurationPolicy;
* import com.pulumi.aws.securityhub.ConfigurationPolicyArgs;
* import com.pulumi.aws.securityhub.inputs.ConfigurationPolicyConfigurationPolicyArgs;
* import com.pulumi.aws.securityhub.inputs.ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationArgs;
* import com.pulumi.resources.CustomResourceOptions;
* import java.util.List;
* import java.util.ArrayList;
* import java.util.Map;
* import java.io.File;
* import java.nio.file.Files;
* import java.nio.file.Paths;
*
* public class App {
* public static void main(String[] args) {
* Pulumi.run(App::stack);
* }
*
* public static void stack(Context ctx) {
* var disabled = new ConfigurationPolicy("disabled", ConfigurationPolicyArgs.builder()
* .name("Custom Controls")
* .description("This is an example of configuration policy with custom control settings")
* .configurationPolicy(ConfigurationPolicyConfigurationPolicyArgs.builder()
* .serviceEnabled(true)
* .enabledStandardArns(
* "arn:aws:securityhub:us-east-1::standards/aws-foundational-security-best-practices/v/1.0.0",
* "arn:aws:securityhub:::ruleset/cis-aws-foundations-benchmark/v/1.2.0")
* .securityControlsConfiguration(ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationArgs.builder()
* .enabledControlIdentifiers(
* "APIGateway.1",
* "IAM.7")
* .securityControlCustomParameters(
* ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterArgs.builder()
* .securityControlId("APIGateway.1")
* .parameters(ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterArgs.builder()
* .name("loggingLevel")
* .valueType("CUSTOM")
* .enum_(ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterEnumArgs.builder()
* .value("INFO")
* .build())
* .build())
* .build(),
* ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterArgs.builder()
* .securityControlId("IAM.7")
* .parameters(
* ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterArgs.builder()
* .name("RequireLowercaseCharacters")
* .valueType("CUSTOM")
* .bool(ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterBoolArgs.builder()
* .value(false)
* .build())
* .build(),
* ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterArgs.builder()
* .name("MaxPasswordAge")
* .valueType("CUSTOM")
* .int_(ConfigurationPolicyConfigurationPolicySecurityControlsConfigurationSecurityControlCustomParameterParameterIntArgs.builder()
* .value(60)
* .build())
* .build())
* .build())
* .build())
* .build())
* .build(), CustomResourceOptions.builder()
* .dependsOn(example)
* .build());
*
* }
* }
* }
*
* <!--End PulumiCodeChooser -->
*
* ## Import
*
* Using `pulumi import`, import an existing Security Hub enabled account using the universally unique identifier (UUID) of the policy. For example:
*
* ```sh
* $ pulumi import aws:securityhub/configurationPolicy:ConfigurationPolicy example "00000000-1111-2222-3333-444444444444"
* ```
*
*/
@ResourceType(type="aws:securityhub/configurationPolicy:ConfigurationPolicy")
public class ConfigurationPolicy extends com.pulumi.resources.CustomResource {
@Export(name="arn", refs={String.class}, tree="[0]")
private Output arn;
public Output arn() {
return this.arn;
}
/**
* Defines how Security Hub is configured. See below.
*
*/
@Export(name="configurationPolicy", refs={ConfigurationPolicyConfigurationPolicy.class}, tree="[0]")
private Output configurationPolicy;
/**
* @return Defines how Security Hub is configured. See below.
*
*/
public Output configurationPolicy() {
return this.configurationPolicy;
}
/**
* The description of the configuration policy.
*
*/
@Export(name="description", refs={String.class}, tree="[0]")
private Output* @Nullable */ String> description;
/**
* @return The description of the configuration policy.
*
*/
public Output> description() {
return Codegen.optional(this.description);
}
/**
* The name of the configuration policy.
*
*/
@Export(name="name", refs={String.class}, tree="[0]")
private Output name;
/**
* @return The name of the configuration policy.
*
*/
public Output name() {
return this.name;
}
/**
*
* @param name The _unique_ name of the resulting resource.
*/
public ConfigurationPolicy(String name) {
this(name, ConfigurationPolicyArgs.Empty);
}
/**
*
* @param name The _unique_ name of the resulting resource.
* @param args The arguments to use to populate this resource's properties.
*/
public ConfigurationPolicy(String name, ConfigurationPolicyArgs args) {
this(name, args, null);
}
/**
*
* @param name The _unique_ name of the resulting resource.
* @param args The arguments to use to populate this resource's properties.
* @param options A bag of options that control this resource's behavior.
*/
public ConfigurationPolicy(String name, ConfigurationPolicyArgs args, @Nullable com.pulumi.resources.CustomResourceOptions options) {
super("aws:securityhub/configurationPolicy:ConfigurationPolicy", name, args == null ? ConfigurationPolicyArgs.Empty : args, makeResourceOptions(options, Codegen.empty()));
}
private ConfigurationPolicy(String name, Output id, @Nullable ConfigurationPolicyState state, @Nullable com.pulumi.resources.CustomResourceOptions options) {
super("aws:securityhub/configurationPolicy:ConfigurationPolicy", name, state, makeResourceOptions(options, id));
}
private static com.pulumi.resources.CustomResourceOptions makeResourceOptions(@Nullable com.pulumi.resources.CustomResourceOptions options, @Nullable Output id) {
var defaultOptions = com.pulumi.resources.CustomResourceOptions.builder()
.version(Utilities.getVersion())
.build();
return com.pulumi.resources.CustomResourceOptions.merge(defaultOptions, options, id);
}
/**
* Get an existing Host resource's state with the given name, ID, and optional extra
* properties used to qualify the lookup.
*
* @param name The _unique_ name of the resulting resource.
* @param id The _unique_ provider ID of the resource to lookup.
* @param state
* @param options Optional settings to control the behavior of the CustomResource.
*/
public static ConfigurationPolicy get(String name, Output id, @Nullable ConfigurationPolicyState state, @Nullable com.pulumi.resources.CustomResourceOptions options) {
return new ConfigurationPolicy(name, id, state, options);
}
}
© 2015 - 2025 Weber Informatics LLC | Privacy Policy