We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi
We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi
Resource type definition for AWS::EventsV2::ResourcePolicy, the resource policy of an Amazon EventBridge event bus. This manages only the resource policy named “default”, which the bus owner writes. It does not manage the policy named “AWS_RAM”, which AWS Resource Access Manager owns on behalf of the bus owner. If the bus already has a default policy, creating this resource fails. Deleting this resource removes all permissions granted by it. An explicit Deny in this policy takes precedence over an Allow in the “AWS_RAM” policy, so deleting this resource can widen access. Set DeletionPolicy: Retain if the policy carries a Deny that you rely on. Required permissions: events:PutResourcePolicy, events:GetResourcePolicy, and events:DeleteResourcePolicy. Listing resources of this type also requires events:ListEventBuses and events:ListResourcePolicies.
Create ResourcePolicy Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new ResourcePolicy(name: string, args: ResourcePolicyArgs, opts?: CustomResourceOptions);@overload
def ResourcePolicy(resource_name: str,
args: ResourcePolicyArgs,
opts: Optional[ResourceOptions] = None)
@overload
def ResourcePolicy(resource_name: str,
opts: Optional[ResourceOptions] = None,
event_bus_arn: Optional[str] = None,
policy_document: Optional[Any] = None)func NewResourcePolicy(ctx *Context, name string, args ResourcePolicyArgs, opts ...ResourceOption) (*ResourcePolicy, error)public ResourcePolicy(string name, ResourcePolicyArgs args, CustomResourceOptions? opts = null)
public ResourcePolicy(String name, ResourcePolicyArgs args)
public ResourcePolicy(String name, ResourcePolicyArgs args, CustomResourceOptions options)
type: aws-native:eventsv2:ResourcePolicy
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "aws-native_eventsv2_resource_policy" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args ResourcePolicyArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args ResourcePolicyArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args ResourcePolicyArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args ResourcePolicyArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args ResourcePolicyArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
ResourcePolicy Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The ResourcePolicy resource accepts the following input properties:
- Event
Bus stringArn - The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
- Policy
Document object The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.
Search the CloudFormation User Guide for
AWS::EventsV2::ResourcePolicyfor more information about the expected schema for this property.
- Event
Bus stringArn - The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
- Policy
Document interface{} The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.
Search the CloudFormation User Guide for
AWS::EventsV2::ResourcePolicyfor more information about the expected schema for this property.
- event_
bus_ stringarn - The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
- policy_
document any The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.
Search the CloudFormation User Guide for
AWS::EventsV2::ResourcePolicyfor more information about the expected schema for this property.
- event
Bus StringArn - The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
- policy
Document Object The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.
Search the CloudFormation User Guide for
AWS::EventsV2::ResourcePolicyfor more information about the expected schema for this property.
- event
Bus stringArn - The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
- policy
Document any The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.
Search the CloudFormation User Guide for
AWS::EventsV2::ResourcePolicyfor more information about the expected schema for this property.
- event_
bus_ strarn - The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
- policy_
document Any The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.
Search the CloudFormation User Guide for
AWS::EventsV2::ResourcePolicyfor more information about the expected schema for this property.
- event
Bus StringArn - The Amazon Resource Name (ARN) of the event bus whose resource policy this is. The bus must already exist. This resource does not create it.
- policy
Document Any The resource policy document, as a JSON object. The document can be up to 20 KB. This quota is adjustable. An empty object is not a valid policy. To remove the policy, delete this resource. The principals in the document must exist and be visible to the service when the policy is written. When you create a new IAM role or user, that principal might not be immediately visible to the service. You might need to enforce a delay before you include it in the document. For more information, see "Changes that I make are not always immediately visible" in the IAM User Guide. Declare Version. Write AWS account and role principals as ARNs rather than as account IDs. Write a single Action, Resource, or principal value as a scalar rather than as a one-element list. The service returns these forms as you wrote them. It normalizes other forms, and a normalized value can appear as drift. A stack update replaces the whole policy with this document, including any change made outside CloudFormation. For more information about event bus resource policies, see the Amazon EventBridge User Guide.
Search the CloudFormation User Guide for
AWS::EventsV2::ResourcePolicyfor more information about the expected schema for this property.
Outputs
All input properties are implicitly available as output properties. Additionally, the ResourcePolicy resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Revision
Id string - The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
- Id string
- The provider-assigned unique ID for this managed resource.
- Revision
Id string - The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
- id string
- The provider-assigned unique ID for this managed resource.
- revision_
id string - The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
- id String
- The provider-assigned unique ID for this managed resource.
- revision
Id String - The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
- id string
- The provider-assigned unique ID for this managed resource.
- revision
Id string - The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
- id str
- The provider-assigned unique ID for this managed resource.
- revision_
id str - The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
- id String
- The provider-assigned unique ID for this managed resource.
- revision
Id String - The revision identifier the service assigned to the stored policy. The identifier changes on every successful write.
Package Details
- Repository
- AWS Native pulumi/pulumi-aws-native
- License
- Apache-2.0
We recommend new projects start with resources from the AWS provider.
published on Monday, Sep 28, 2026 by Pulumi