class CfnResourcePolicy (construct)
| Language | Type name |
|---|---|
.NET | Amazon.CDK.AWS.Lambda.CfnResourcePolicy |
Go | github.com/aws/aws-cdk-go/awscdk/v2/awslambda#CfnResourcePolicy |
Java | software.amazon.awscdk.services.lambda.CfnResourcePolicy |
Python | aws_cdk.aws_lambda.CfnResourcePolicy |
TypeScript | aws-cdk-lib » aws_lambda » CfnResourcePolicy |
Implements
IConstruct, IDependable, IInspectable, IResource, IEnvironment
Use the AWS::Lambda::ResourcePolicy resource to attach a resource-based policy to a LAM resource.
A resource-based policy applies to a single LAM resource, for example, a function, function version, or function alias. To learn more about using resource-based policies with LAM, see Working with resource-based policies in in the Developer Guide.
You can use resource-based policies to grant permissions to other AWS services, AWS accounts and organizations, and IAM users and roles to access your LAM resource. You can also deny access to specific entities, and use the full range of IAM global condition keys to further restrict who has access to your LAM resource. For example, you can limit access to calls originating from a specified IP address or VPC.
A resource-based policy is a JSON document containing a number of statements. Each statement defines the entities you want to grant permission to, the API actions you want to allow or deny, and the LAM resource you want the statement to apply to. A statement can also optionally include an array of logical conditions using the IAM global condition keys.
To use the AWS::Lambda::ResourcePolicy resource, make sure that you have the resource-based policy permissions for Lambda.
To learn more about creating resource-based policies, see Policies and permissions in in the User Guide. For more information about example policies for providing permissions to AWS services, other AWS accounts, and IAM users and roles, see Example resource-based policies for functions in the Developer Guide.
Avoid mixing permission resource types
To grant permissions to access your function, we recommend using the AWS::Lambda::ResourcePolicy resource to set access permissions. With this resource, you have more flexibility and fine-grained control than AWS::Lambda::Permission. This resource grants an AWS service or another account permission to call a particular API action on a function.
You can also use the AWS::Lambda::Permission resource, however using both AWS::Lambda::Permission and AWS::Lambda::ResourcePolicy to set permissions on a function can result in errors. Permissions defined in AWS::Lambda::Permission can be unintentionally overwritten, whether in a single CFN stack or across multiple stacks. Don't use both resource types to set permissions on a function.
To migrate existing permissions for a function from AWS::Lambda::Permission to AWS::Lambda::ResourcePolicy, do the following:
- Set a
Retaindeletion policy on theAWS::Lambda::Permissionresources you want to migrate. This is necessary so that Lambda does not delete statements with the same statement ID when you delete these resources. - Use the GetResourcePolicyLAM API to retrieve the resource-based policy currently attached to the function.
- Use this policy to create a new
AWS::Lambda::ResourcePolicyresource. - Delete all the existing
AWS::Lambda::Permissionresources for the function.
Example
// The code below shows an example of how to instantiate this type.
// The values are placeholders you should change.
import { aws_lambda as lambda } from 'aws-cdk-lib';
declare const policyDocument: any;
const cfnResourcePolicy = new lambda.CfnResourcePolicy(this, 'MyCfnResourcePolicy', {
policyDocument: policyDocument,
resourceArn: 'resourceArn',
});
Initializer
new CfnResourcePolicy(scope: Construct, id: string, props: CfnResourcePolicyProps)
Parameters
- scope
Construct— Scope in which this resource is defined. - id
string— Construct identifier for this resource (unique in its scope). - props
Cfn— Resource properties.Resource Policy Props
Create a new AWS::Lambda::ResourcePolicy.
Construct Props
| Name | Type | Description |
|---|---|---|
| policy | any | The policy document you want to add to your LAM resource. |
| resource | string | The Amazon Resource Name (ARN) of the LAM resource you want to add the policy to. |
policyDocument
Type:
any
The policy document you want to add to your LAM resource.
This is formatted as a JSON string. For more information, see Working with resource-based policies in in the Developer Guide.
resourceArn
Type:
string
The Amazon Resource Name (ARN) of the LAM resource you want to add the policy to.
For a function, you can use a qualified or an unqualified ARN. The value must be a complete ARN, and the operation does not accept wildcard characters.
Properties
| Name | Type | Description |
|---|---|---|
| cfn | ICfn | Options for this resource, such as condition, update policy etc. |
| cfn | { [string]: any } | |
| cfn | { [string]: string } | |
| cfn | string | AWS resource type. |
| creation | string[] | |
| env | Resource | |
| logical | string | The logical ID for this CloudFormation stack element. |
| node | Node | The tree node. |
| policy | any | The policy document you want to add to your LAM resource. |
| ref | string | Return a string that will be resolved to a CloudFormation { Ref } for this element. |
| resource | string | The Amazon Resource Name (ARN) of the LAM resource you want to add the policy to. |
| resource | Resource | A reference to a ResourcePolicy resource. |
| stack | Stack | The stack in which this element is defined. |
| static CFN_RESOURCE_TYPE_NAME | string | The CloudFormation resource type name for this resource class. |
cfnOptions
Type:
ICfn
Options for this resource, such as condition, update policy etc.
cfnProperties
Type:
{ [string]: any }
cfnPropertyNames
Type:
{ [string]: string }
cfnResourceType
Type:
string
AWS resource type.
creationStack
Type:
string[]
env
Type:
Resource
logicalId
Type:
string
The logical ID for this CloudFormation stack element.
The logical ID of the element is calculated from the path of the resource node in the construct tree.
To override this value, use overrideLogicalId(newLogicalId).
node
Type:
Node
The tree node.
policyDocument
Type:
any
The policy document you want to add to your LAM resource.
ref
Type:
string
Return a string that will be resolved to a CloudFormation { Ref } for this element.
If, by any chance, the intrinsic reference of a resource is not a string, you could
coerce it to an IResolvable through Lazy.any({ produce: resource.ref }).
resourceArn
Type:
string
The Amazon Resource Name (ARN) of the LAM resource you want to add the policy to.
resourcePolicyRef
Type:
Resource
A reference to a ResourcePolicy resource.
stack
Type:
Stack
The stack in which this element is defined.
CfnElements must be defined within a stack scope (directly or indirectly).
static CFN_RESOURCE_TYPE_NAME
Type:
string
The CloudFormation resource type name for this resource class.
Methods
| Name | Description |
|---|---|
| add | Syntactic sugar for addOverride(path, undefined). |
| add | Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. |
| add | Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. |
| add | Add a value to the CloudFormation Resource Metadata. |
| add | Adds an override to the synthesized CloudFormation resource. |
| add | Adds an override that deletes the value of a property from the resource definition. |
| add | Adds an override to a resource property. |
| add | Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned. |
| apply | Sets the cross-stack reference strength for this resource. |
| apply | Sets the deletion policy of the resource based on the removal policy specified. |
| cfn | |
| get | Returns a token for an runtime attribute of this resource. |
| get | Retrieve a value value from the CloudFormation Resource Metadata. |
| inspect(inspector) | Examines the CloudFormation resource and discloses attributes. |
| obtain | Retrieves an array of resources and stacks this resource depends on. |
| override | Overrides the auto-generated logical ID with a specific ID. |
| remove | Indicates that this resource no longer depends on another resource. |
| remove | Indicates that this resource no longer depends on another resource. |
| replace | Replaces one dependency with another. |
| to | Returns a string representation of this construct. |
| with(...mixins) | Applies one or more mixins to this construct. |
| protected render | |
| static is | Checks whether the given object is a CfnResourcePolicy. |
addDeletionOverride(path)
public addDeletionOverride(path: string): void
Parameters
- path
string— The path of the value to delete.
Syntactic sugar for addOverride(path, undefined).
addDependency(target)
public addDependency(target: CfnResource): void
⚠️ Deprecated: Use addResourceDependency instead.
Parameters
- target
CfnResource
Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned.
This method has been renamed to addResourceDependency to more clearly
set it apart from construct.node.addDependency. See the documentation
of that function for more details.
addDependsOn(target)
public addDependsOn(target: CfnResource): void
⚠️ Deprecated: Use addResourceDependency instead.
Parameters
- target
CfnResource
Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned.
This can be used for resources across stacks (or nested stack) boundaries and the dependency will automatically be transferred to the relevant scope.
This method has been renamed to addResourceDependency, which makes it
more clear that this method operates at a different level from the
construct-level construct.node.addDependency() mechanism.
addMetadata(key, value)
public addMetadata(key: string, value: any): void
Parameters
- key
string - value
any
Add a value to the CloudFormation Resource Metadata.
Note that this is a different set of metadata from CDK node metadata; this metadata ends up in the stack template under the resource, whereas CDK node metadata ends up in the Cloud Assembly.](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html
Note that this is a different set of metadata from CDK node metadata; this metadata ends up in the stack template under the resource, whereas CDK node metadata ends up in the Cloud Assembly.)
addOverride(path, value)
public addOverride(path: string, value: any): void
Parameters
- path
string— - The path of the property, you can use dot notation to override values in complex types. - value
any— - The value.
Adds an override to the synthesized CloudFormation resource.
To add a
property override, either use addPropertyOverride or prefix path with
"Properties." (i.e. Properties.TopicName).
If the override is nested, separate each nested level using a dot (.) in the path parameter. If there is an array as part of the nesting, specify the index in the path.
To include a literal . in the property name, prefix with a \. In most
programming languages you will need to write this as "\\." because the
\ itself will need to be escaped.
For example,
cfnResource.addOverride('Properties.GlobalSecondaryIndexes.0.Projection.NonKeyAttributes', ['myattribute']);
cfnResource.addOverride('Properties.GlobalSecondaryIndexes.1.ProjectionType', 'INCLUDE');
would add the overrides
"Properties": {
"GlobalSecondaryIndexes": [
{
"Projection": {
"NonKeyAttributes": [ "myattribute" ]
...
}
...
},
{
"ProjectionType": "INCLUDE"
...
},
]
...
}
The value argument to addOverride will not be processed or translated
in any way. Pass raw JSON values in here with the correct capitalization
for CloudFormation. If you pass CDK classes or structs, they will be
rendered with lowercased key names, and CloudFormation will reject the
template.
addPropertyDeletionOverride(propertyPath)
public addPropertyDeletionOverride(propertyPath: string): void
Parameters
- propertyPath
string— The path to the property.
Adds an override that deletes the value of a property from the resource definition.
addPropertyOverride(propertyPath, value)
public addPropertyOverride(propertyPath: string, value: any): void
Parameters
- propertyPath
string— The path of the property. - value
any— The value.
Adds an override to a resource property.
Syntactic sugar for addOverride("Properties.<...>", value).
addResourceDependency(target, reason?)
public addResourceDependency(target: CfnResource, reason?: string): void
Parameters
- target
CfnResource - reason
string
Indicates that this resource depends on another resource and cannot be provisioned unless the other resource has been successfully provisioned.
This can be used for resources across stacks (or nested stack) boundaries and the dependency will automatically be transferred to the relevant scope.
This method only adds dependencies between L1 resources. If you are
looking for a generic construct-to-construct dependency mechanism that works
for all constructs including L2s, use construct.node.addDependency instead.
applyCrossStackReferenceStrength(strength)
public applyCrossStackReferenceStrength(strength: ReferenceStrength): void
Parameters
- strength
Reference— - The reference strength to use for this resource.Strength
Sets the cross-stack reference strength for this resource.
When set, any cross-stack reference to this resource will use the specified strength instead of the global default from the consuming stack's context.
applyRemovalPolicy(policy?, options?)
public applyRemovalPolicy(policy?: RemovalPolicy, options?: RemovalPolicyOptions): void
Parameters
- policy
RemovalPolicy - options
RemovalPolicy Options
Sets the deletion policy of the resource based on the removal policy specified.
The Removal Policy controls what happens to this resource when it stops being managed by CloudFormation, either because you've removed it from the CDK application or because you've made a change that requires the resource to be replaced.
The resource can be deleted (RemovalPolicy.DESTROY), or left in your AWS
account for data recovery and cleanup later (RemovalPolicy.RETAIN). In some
cases, a snapshot can be taken of the resource prior to deletion
(RemovalPolicy.SNAPSHOT). A list of resources that support this policy
can be found in the following link:
cfnPropertyName(cdkPropertyName)
public cfnPropertyName(cdkPropertyName: string): string
Parameters
- cdkPropertyName
string
Returns
string
getAtt(attributeName, typeHint?)
public getAtt(attributeName: string, typeHint?: ResolutionTypeHint): Reference
Parameters
- attributeName
string— The name of the attribute. - typeHint
ResolutionType Hint
Returns
Returns a token for an runtime attribute of this resource.
Ideally, use generated attribute accessors (e.g. resource.arn), but this can be used for future compatibility
in case there is no generated attribute.
getMetadata(key)
public getMetadata(key: string): any
Parameters
- key
string
Returns
any
Retrieve a value value from the CloudFormation Resource Metadata.
Note that this is a different set of metadata from CDK node metadata; this metadata ends up in the stack template under the resource, whereas CDK node metadata ends up in the Cloud Assembly.](https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/metadata-section-structure.html
Note that this is a different set of metadata from CDK node metadata; this metadata ends up in the stack template under the resource, whereas CDK node metadata ends up in the Cloud Assembly.)
inspect(inspector)
public inspect(inspector: TreeInspector): void
Parameters
- inspector
Tree— tree inspector to collect and process attributes.Inspector
Examines the CloudFormation resource and discloses attributes.
obtainDependencies()
public obtainDependencies(): (Stack | CfnResource)[]
Returns
(Stack|CfnResource )[]
Retrieves an array of resources and stacks this resource depends on.
For resources depended on directly, returns the CfnResource object. For
dependencies on other stacks, returns the Stack object. The order of the
array is not guaranteed.
overrideLogicalId(newLogicalId)
public overrideLogicalId(newLogicalId: string): void
Parameters
- newLogicalId
string— The new logical ID to use for this stack element.
Overrides the auto-generated logical ID with a specific ID.
removeDependency(target)
public removeDependency(target: CfnResource): void
⚠️ Deprecated: Use removeResourceDependency instead
Parameters
- target
CfnResource
Indicates that this resource no longer depends on another resource.
This can be used for resources across stacks (including nested stacks) and the dependency will automatically be removed from the relevant scope.
removeResourceDependency(target)
public removeResourceDependency(target: CfnResource): void
Parameters
- target
CfnResource
Indicates that this resource no longer depends on another resource.
This can be used for resources across stacks (including nested stacks) and the dependency will automatically be removed from the relevant scope.
replaceDependency(target, newTarget)
public replaceDependency(target: CfnResource, newTarget: CfnResource): void
Parameters
- target
Cfn— The dependency to replace.Resource - newTarget
Cfn— The new dependency to add.Resource
Replaces one dependency with another.
toString()
public toString(): string
Returns
string
Returns a string representation of this construct.
with(...mixins)
public with(...mixins: IMixin[]): IConstruct
Parameters
- mixins
IMixin
Returns
Applies one or more mixins to this construct.
Mixins are applied in order. The list of constructs is captured at the
start of the call, so constructs added by a mixin will not be visited.
Use multiple with() calls if subsequent mixins should apply to added
constructs.
protected renderProperties(props)
protected renderProperties(props: { [string]: any }): { [string]: any }
Parameters
- props
{ [string]: any }
Returns
{ [string]: any }
static isCfnResourcePolicy(x)
public static isCfnResourcePolicy(x: any): boolean
Parameters
- x
any
Returns
boolean
Checks whether the given object is a CfnResourcePolicy.

.NET
Go
Java
Python
TypeScript