1. Registry
  2. Packages
  3. AWS Cloud Control
  4. API Docs
  5. eventsv2
  6. ResourcePolicy

We recommend new projects start with resources from the AWS provider.

Viewing docs for AWS Cloud Control v1.81.0
published on Monday, Sep 28, 2026 by Pulumi
aws-native logo aws-native logo

We recommend new projects start with resources from the AWS provider.

Viewing docs for AWS Cloud Control v1.81.0
published on Monday, Sep 28, 2026 by Pulumi

    Resource type definition for AWS::EventsV2::ResourcePolicy, the resource policy of an Amazon EventBridge event bus. This manages only the resource policy named “default”, which the bus owner writes. It does not manage the policy named “AWS_RAM”, which AWS Resource Access Manager owns on behalf of the bus owner. If the bus already has a default policy, creating this resource fails. Deleting this resource removes all permissions granted by it. An explicit Deny in this policy takes precedence over an Allow in the “AWS_RAM” policy, so deleting this resource can widen access. Set DeletionPolicy: Retain if the policy carries a Deny that you rely on. Required permissions: events:PutResourcePolicy, events:GetResourcePolicy, and events:DeleteResourcePolicy. Listing resources of this type also requires events:ListEventBuses and events:ListResourcePolicies.

    Create ResourcePolicy Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new ResourcePolicy(name: string, args: ResourcePolicyArgs, opts?: CustomResourceOptions);
    @overload
    def ResourcePolicy(resource_name: str,
                       args: ResourcePolicyArgs,
                       opts: Optional[ResourceOptions] = None)
    
    @overload
    def ResourcePolicy(resource_name: str,
                       opts: Optional[ResourceOptions] = None,
                       event_bus_arn: Optional[str] = None,
                       policy_document: Optional[Any] = None)
    func NewResourcePolicy(ctx *Context, name string, args ResourcePolicyArgs, opts ...ResourceOption) (*ResourcePolicy, error)
    public ResourcePolicy(string name, ResourcePolicyArgs args, CustomResourceOptions? opts = null)
    public ResourcePolicy(String name, ResourcePolicyArgs args)
    public ResourcePolicy(String name, ResourcePolicyArgs args, CustomResourceOptions options)
    
    type: aws-native:eventsv2:ResourcePolicy
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "aws-native_eventsv2_resource_policy" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args ResourcePolicyArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args ResourcePolicyArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args ResourcePolicyArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args ResourcePolicyArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args ResourcePolicyArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    ResourcePolicy Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The ResourcePolicy resource accepts the following input properties:

    EventBusArn string
    The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
    PolicyDocument object

    The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.

    Search the CloudFormation User Guide for AWS::EventsV2::ResourcePolicy for more information about the expected schema for this property.

    EventBusArn string
    The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
    PolicyDocument interface{}

    The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.

    Search the CloudFormation User Guide for AWS::EventsV2::ResourcePolicy for more information about the expected schema for this property.

    event_bus_arn string
    The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
    policy_document any

    The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.

    Search the CloudFormation User Guide for AWS::EventsV2::ResourcePolicy for more information about the expected schema for this property.

    eventBusArn String
    The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
    policyDocument Object

    The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.

    Search the CloudFormation User Guide for AWS::EventsV2::ResourcePolicy for more information about the expected schema for this property.

    eventBusArn string
    The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
    policyDocument any

    The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.

    Search the CloudFormation User Guide for AWS::EventsV2::ResourcePolicy for more information about the expected schema for this property.

    event_bus_arn str
    The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
    policy_document Any

    The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.

    Search the CloudFormation User Guide for AWS::EventsV2::ResourcePolicy for more information about the expected schema for this property.

    eventBusArn String
    The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
    policyDocument Any

    The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.

    Search the CloudFormation User Guide for AWS::EventsV2::ResourcePolicy for more information about the expected schema for this property.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the ResourcePolicy resource produces the following output properties:

    Id string
    The provider-assigned unique ID for this managed resource.
    RevisionId string
    The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
    Id string
    The provider-assigned unique ID for this managed resource.
    RevisionId string
    The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
    id string
    The provider-assigned unique ID for this managed resource.
    revision_id string
    The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
    id String
    The provider-assigned unique ID for this managed resource.
    revisionId String
    The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
    id string
    The provider-assigned unique ID for this managed resource.
    revisionId string
    The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
    id str
    The provider-assigned unique ID for this managed resource.
    revision_id str
    The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
    id String
    The provider-assigned unique ID for this managed resource.
    revisionId String
    The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.

    Package Details

    Repository
    AWS Native pulumi/pulumi-aws-native
    License
    Apache-2.0
    aws-native logo aws-native logo

    We recommend new projects start with resources from the AWS provider.

    Viewing docs for AWS Cloud Control v1.81.0
    published on Monday, Sep 28, 2026 by Pulumi

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial