ModifyClientVpnEndpointAuthorizationPolicy
Creates or updates the authorization policy for a Client VPN endpoint. A Client VPN endpoint can have one authorization policy. If a policy already exists for the endpoint, the values that you specify replace the corresponding values in the existing policy, and values that you do not specify remain unchanged.
Request Parameters
The following parameters are for this specific action. For more information about required and optional parameters that are common to all actions, see Common Query Parameters.
- ClientToken
-
Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see Ensuring idempotency.
Type: String
Required: No
- ClientVpnEndpointId
-
The ID of the Client VPN endpoint.
Type: String
Required: Yes
- Description
-
A brief description of the authorization policy.
Type: String
Required: No
- DryRun
-
Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is
DryRunOperation. Otherwise, it isUnauthorizedOperation.Type: Boolean
Required: No
- PolicyDocument
-
The authorization policy document, written in the Cedar policy language. This parameter is required when you create the authorization policy for a Client VPN endpoint that does not already have one.
Type: String
Required: No
- ShadowMode
-
Specifies whether the authorization policy is evaluated in shadow mode. Possible values include:
-
enabled- The authorization policy is evaluated and the results are logged, but access is not enforced. -
disabled- The authorization policy is enforced.
The default value is
disabled.Type: String
Valid Values:
enabled | disabledRequired: No
-
Response Elements
The following elements are returned by the service.
- requestId
-
The ID of the request.
Type: String
- status
-
The current state of the authorization policy.
Type: String
Valid Values:
creating | updating | active | failed | deleting
Errors
For information about the errors that are common to all actions, see Common Error Types.
Examples
Example
This example creates or updates the authorization policy for a Client VPN endpoint.
Sample Request
https://ec2.amazonaws.com/?Action=ModifyClientVpnEndpointAuthorizationPolicy
&ClientVpnEndpointId=cvpn-endpoint-00c5d11fc4EXAMPLE
&PolicyDocument=permit(principal,%20action,%20resource)%20when%20%7B%20context.crowdstrike.assessment.overall%20%3E%2080%20%7D;
&ShadowMode=disabled
&AUTHPARAMS
Sample Response
<ModifyClientVpnEndpointAuthorizationPolicyResponse xmlns="http://ec2.amazonaws.com/doc/2016-11-15/">
<requestId>5ef84b7f-505e-4e39-80cd-a11dbEXAMPLE</requestId>
<status>updating</status>
</ModifyClientVpnEndpointAuthorizationPolicyResponse>
See Also
For more information about using this API in one of the language-specific AWS SDKs, see the following: