EC2 / Client / modify_client_vpn_endpoint_authorization_policy

modify_client_vpn_endpoint_authorization_policy

EC2.Client.modify_client_vpn_endpoint_authorization_policy(**kwargs)

Creates or updates the authorization policy for a Client VPN endpoint. A Client VPN endpoint can have one authorization policy. If a policy already exists for the endpoint, the values that you specify replace the corresponding values in the existing policy, and values that you do not specify remain unchanged.

See also: AWS API Documentation

Request Syntax

response = client.modify_client_vpn_endpoint_authorization_policy(
    ClientVpnEndpointId='string',
    PolicyDocument='string',
    Description='string',
    ShadowMode='enabled'|'disabled',
    ClientToken='string',
    DryRun=True|False
)
Parameters:
  • ClientVpnEndpointId (string) –

    [REQUIRED]

    The ID of the Client VPN endpoint.

  • PolicyDocument (string) – The authorization policy document, written in the Cedar policy language. This parameter is required when you create the authorization policy for a Client VPN endpoint that does not already have one.

  • Description (string) – A brief description of the authorization policy.

  • ShadowMode (string) –

    Specifies whether the authorization policy is evaluated in shadow mode. Possible values include:

    • enabled - The authorization policy is evaluated and the results are logged, but access is not enforced.

    • disabled - The authorization policy is enforced.

    The default value is disabled.

  • ClientToken (string) –

    Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see Ensuring idempotency.

    This field is autopopulated if not provided.

  • DryRun (boolean) – Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

Return type:

dict

Returns:

Response Syntax

{
    'Status': 'creating'|'updating'|'active'|'failed'|'deleting'
}

Response Structure

  • (dict) –

    • Status (string) –

      The current state of the authorization policy.