published on Monday, Sep 21, 2026 by Formal
published on Monday, Sep 21, 2026 by Formal
Controls which Native User V3 a session connects to a Resource as using a CEL expression. Enable Native Users V3 on the Resource separately with nativeUsersV3Enabled.
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as formal from "@formalco/pulumi";
const db = new formal.Resource("db", {
name: "analytics-postgres",
hostname: "analytics.internal",
technology: "postgres",
port: 5432,
nativeUsersV3Enabled: true,
});
const admin = new formal.NativeUserV3("admin", {
basic: {
password: {
environmentVariable: "ANALYTICS_ADMIN_PASSWORD",
},
username: "app_admin",
},
resourceId: db.id,
label: "admin",
});
const readOnly = new formal.NativeUserV3("read_only", {
basic: {
password: {
environmentVariable: "ANALYTICS_READONLY_PASSWORD",
},
username: "app_readonly",
},
resourceId: db.id,
label: "read-only",
});
// Sessions from the admins group connect as app_admin; everyone else connects as
// app_readonly.
const dbResourceNativeUserSelection = new formal.ResourceNativeUserSelection("db", {
resourceId: db.id,
cel: pulumi.interpolate`\"admins\" in user.groups ? \"${admin.id}\"
: \"${readOnly.id}\"
`,
});
import pulumi
import pulumi_formal as formal
db = formal.Resource("db",
name="analytics-postgres",
hostname="analytics.internal",
technology="postgres",
port=5432,
native_users_v3_enabled=True)
admin = formal.NativeUserV3("admin",
basic={
"password": {
"environment_variable": "ANALYTICS_ADMIN_PASSWORD",
},
"username": "app_admin",
},
resource_id=db.id,
label="admin")
read_only = formal.NativeUserV3("read_only",
basic={
"password": {
"environment_variable": "ANALYTICS_READONLY_PASSWORD",
},
"username": "app_readonly",
},
resource_id=db.id,
label="read-only")
# Sessions from the admins group connect as app_admin; everyone else connects as
# app_readonly.
db_resource_native_user_selection = formal.ResourceNativeUserSelection("db",
resource_id=db.id,
cel=pulumi.Output.all(
adminId=admin.id,
readOnlyId=read_only.id
).apply(lambda resolved_outputs: f"""\"admins\" in user.groups ? \"{resolved_outputs['adminId']}\"
: \"{resolved_outputs['readOnlyId']}\"
""")
)
package main
import (
"fmt"
"github.com/formalco/pulumi-formal/sdk/go/formal"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
db, err := formal.NewResource(ctx, "db", &formal.ResourceArgs{
Name: pulumi.String("analytics-postgres"),
Hostname: pulumi.String("analytics.internal"),
Technology: pulumi.String("postgres"),
Port: pulumi.Int(5432),
NativeUsersV3Enabled: pulumi.Bool(true),
})
if err != nil {
return err
}
admin, err := formal.NewNativeUserV3(ctx, "admin", &formal.NativeUserV3Args{
Basic: &formal.NativeUserV3BasicArgs{
Password: &formal.NativeUserV3BasicPasswordArgs{
EnvironmentVariable: pulumi.String("ANALYTICS_ADMIN_PASSWORD"),
},
Username: pulumi.String("app_admin"),
},
ResourceId: db.ID(),
Label: pulumi.String("admin"),
})
if err != nil {
return err
}
readOnly, err := formal.NewNativeUserV3(ctx, "read_only", &formal.NativeUserV3Args{
Basic: &formal.NativeUserV3BasicArgs{
Password: &formal.NativeUserV3BasicPasswordArgs{
EnvironmentVariable: pulumi.String("ANALYTICS_READONLY_PASSWORD"),
},
Username: pulumi.String("app_readonly"),
},
ResourceId: db.ID(),
Label: pulumi.String("read-only"),
})
if err != nil {
return err
}
// Sessions from the admins group connect as app_admin; everyone else connects as
// app_readonly.
_, err = formal.NewResourceNativeUserSelection(ctx, "db", &formal.ResourceNativeUserSelectionArgs{
ResourceId: db.ID(),
Cel: pulumi.All(admin.ID(), readOnly.ID()).ApplyT(func(_args []interface{}) (string, error) {
adminId := _args[0].(string)
readOnlyId := _args[1].(string)
return fmt.Sprintf("\\\"admins\\\" in user.groups ? \\\"%v\\\"\n: \\\"%v\\\"\n", adminId, readOnlyId), nil
}).(pulumi.StringOutput),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Pulumi = Formal.Pulumi;
return await Deployment.RunAsync(() =>
{
var db = new Pulumi.Resource("db", new()
{
Name = "analytics-postgres",
Hostname = "analytics.internal",
Technology = "postgres",
Port = 5432,
NativeUsersV3Enabled = true,
});
var admin = new Pulumi.NativeUserV3("admin", new()
{
Basic = new Pulumi.Inputs.NativeUserV3BasicArgs
{
Password = new Pulumi.Inputs.NativeUserV3BasicPasswordArgs
{
EnvironmentVariable = "ANALYTICS_ADMIN_PASSWORD",
},
Username = "app_admin",
},
ResourceId = db.Id,
Label = "admin",
});
var readOnly = new Pulumi.NativeUserV3("read_only", new()
{
Basic = new Pulumi.Inputs.NativeUserV3BasicArgs
{
Password = new Pulumi.Inputs.NativeUserV3BasicPasswordArgs
{
EnvironmentVariable = "ANALYTICS_READONLY_PASSWORD",
},
Username = "app_readonly",
},
ResourceId = db.Id,
Label = "read-only",
});
// Sessions from the admins group connect as app_admin; everyone else connects as
// app_readonly.
var dbResourceNativeUserSelection = new Pulumi.ResourceNativeUserSelection("db", new()
{
ResourceId = db.Id,
Cel = Output.Tuple(admin.Id, readOnly.Id).Apply(values =>
{
var adminId = values.Item1;
var readOnlyId = values.Item2;
return @$"\""admins\"" in user.groups ? \""{adminId}\""
: \""{readOnlyId}\""
";
}),
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.formal.Resource;
import com.pulumi.formal.ResourceArgs;
import com.pulumi.formal.NativeUserV3;
import com.pulumi.formal.NativeUserV3Args;
import com.pulumi.formal.inputs.NativeUserV3BasicArgs;
import com.pulumi.formal.inputs.NativeUserV3BasicPasswordArgs;
import com.pulumi.formal.ResourceNativeUserSelection;
import com.pulumi.formal.ResourceNativeUserSelectionArgs;
import java.util.ArrayList;
import java.util.Arrays;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var db = new Resource("db", ResourceArgs.builder()
.name("analytics-postgres")
.hostname("analytics.internal")
.technology("postgres")
.port(5432)
.nativeUsersV3Enabled(true)
.build());
var admin = new NativeUserV3("admin", NativeUserV3Args.builder()
.basic(NativeUserV3BasicArgs.builder()
.password(NativeUserV3BasicPasswordArgs.builder()
.environmentVariable("ANALYTICS_ADMIN_PASSWORD")
.build())
.username("app_admin")
.build())
.resourceId(db.id())
.label("admin")
.build());
var readOnly = new NativeUserV3("readOnly", NativeUserV3Args.builder()
.basic(NativeUserV3BasicArgs.builder()
.password(NativeUserV3BasicPasswordArgs.builder()
.environmentVariable("ANALYTICS_READONLY_PASSWORD")
.build())
.username("app_readonly")
.build())
.resourceId(db.id())
.label("read-only")
.build());
// Sessions from the admins group connect as app_admin; everyone else connects as
// app_readonly.
var dbResourceNativeUserSelection = new ResourceNativeUserSelection("dbResourceNativeUserSelection", ResourceNativeUserSelectionArgs.builder()
.resourceId(db.id())
.cel(Output.tuple(admin.id(), readOnly.id()).applyValue(values -> {
var adminId = values.t1;
var readOnlyId = values.t2;
return """
\"admins\" in user.groups ? \"%s\"
: \"%s\"
", adminId,readOnlyId);
}))
.build());
}
}
resources:
db:
type: formal:Resource
properties:
name: analytics-postgres
hostname: analytics.internal
technology: postgres
port: 5432
nativeUsersV3Enabled: true
admin:
type: formal:NativeUserV3
properties:
basic:
password:
environmentVariable: ANALYTICS_ADMIN_PASSWORD
username: app_admin
resourceId: ${db.id}
label: admin
readOnly:
type: formal:NativeUserV3
name: read_only
properties:
basic:
password:
environmentVariable: ANALYTICS_READONLY_PASSWORD
username: app_readonly
resourceId: ${db.id}
label: read-only
# Sessions from the admins group connect as app_admin; everyone else connects as
# app_readonly.
dbResourceNativeUserSelection:
type: formal:ResourceNativeUserSelection
name: db
properties:
resourceId: ${db.id}
cel: |
\"admins\" in user.groups ? \"${admin.id}\"
: \"${readOnly.id}\"
pulumi {
required_providers {
formal = {
source = "pulumi/formal"
}
}
}
resource "formal_resource" "db" {
name = "analytics-postgres"
hostname = "analytics.internal"
technology = "postgres"
port = 5432
native_users_v3_enabled = true
}
resource "formal_nativeuserv3" "admin" {
basic = {
password = {
environment_variable = "ANALYTICS_ADMIN_PASSWORD"
}
username = "app_admin"
}
resource_id = formal_resource.db.id
label = "admin"
}
resource "formal_nativeuserv3" "read_only" {
basic = {
password = {
environment_variable = "ANALYTICS_READONLY_PASSWORD"
}
username = "app_readonly"
}
resource_id = formal_resource.db.id
label = "read-only"
}
# Sessions from the admins group connect as app_admin; everyone else connects as
# app_readonly.
resource "formal_resourcenativeuserselection" "db" {
resource_id = formal_resource.db.id
cel ="\"admins\" in user.groups ? \"${formal_nativeuserv3.admin.id}\"
: \"${formal_nativeuserv3.read_only.id}\"
"
}
Create ResourceNativeUserSelection Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new ResourceNativeUserSelection(name: string, args: ResourceNativeUserSelectionArgs, opts?: CustomResourceOptions);@overload
def ResourceNativeUserSelection(resource_name: str,
args: ResourceNativeUserSelectionArgs,
opts: Optional[ResourceOptions] = None)
@overload
def ResourceNativeUserSelection(resource_name: str,
opts: Optional[ResourceOptions] = None,
cel: Optional[str] = None,
resource_id: Optional[str] = None)func NewResourceNativeUserSelection(ctx *Context, name string, args ResourceNativeUserSelectionArgs, opts ...ResourceOption) (*ResourceNativeUserSelection, error)public ResourceNativeUserSelection(string name, ResourceNativeUserSelectionArgs args, CustomResourceOptions? opts = null)
public ResourceNativeUserSelection(String name, ResourceNativeUserSelectionArgs args)
public ResourceNativeUserSelection(String name, ResourceNativeUserSelectionArgs args, CustomResourceOptions options)
type: formal:ResourceNativeUserSelection
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "formal_resource_native_user_selection" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args ResourceNativeUserSelectionArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args ResourceNativeUserSelectionArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args ResourceNativeUserSelectionArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args ResourceNativeUserSelectionArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args ResourceNativeUserSelectionArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var resourceNativeUserSelectionResource = new Pulumi.ResourceNativeUserSelection("resourceNativeUserSelectionResource", new()
{
Cel = "string",
ResourceId = "string",
});
example, err := formal.NewResourceNativeUserSelection(ctx, "resourceNativeUserSelectionResource", &formal.ResourceNativeUserSelectionArgs{
Cel: pulumi.String("string"),
ResourceId: pulumi.String("string"),
})
resource "formal_resource_native_user_selection" "resourceNativeUserSelectionResource" {
lifecycle {
create_before_destroy = true
}
cel = "string"
resource_id = "string"
}
var resourceNativeUserSelectionResource = new ResourceNativeUserSelection("resourceNativeUserSelectionResource", ResourceNativeUserSelectionArgs.builder()
.cel("string")
.resourceId("string")
.build());
resource_native_user_selection_resource = formal.ResourceNativeUserSelection("resourceNativeUserSelectionResource",
cel="string",
resource_id="string")
const resourceNativeUserSelectionResource = new formal.ResourceNativeUserSelection("resourceNativeUserSelectionResource", {
cel: "string",
resourceId: "string",
});
type: formal:ResourceNativeUserSelection
properties:
cel: string
resourceId: string
ResourceNativeUserSelection Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The ResourceNativeUserSelection resource accepts the following input properties:
- Cel string
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- Resource
Id string - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- Cel string
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- Resource
Id string - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel string
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource_
id string - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel String
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource
Id String - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel string
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource
Id string - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel str
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource_
id str - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel String
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource
Id String - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
Outputs
All input properties are implicitly available as output properties. Additionally, the ResourceNativeUserSelection resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Id string
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id str
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
Look up Existing ResourceNativeUserSelection Resource
Get an existing ResourceNativeUserSelection resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: ResourceNativeUserSelectionState, opts?: CustomResourceOptions): ResourceNativeUserSelection@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
cel: Optional[str] = None,
resource_id: Optional[str] = None) -> ResourceNativeUserSelectionfunc GetResourceNativeUserSelection(ctx *Context, name string, id IDInput, state *ResourceNativeUserSelectionState, opts ...ResourceOption) (*ResourceNativeUserSelection, error)public static ResourceNativeUserSelection Get(string name, Input<string> id, ResourceNativeUserSelectionState? state, CustomResourceOptions? opts = null)public static ResourceNativeUserSelection get(String name, Output<String> id, ResourceNativeUserSelectionState state, CustomResourceOptions options)resources: _: type: formal:ResourceNativeUserSelection get: id: ${id}import {
to = formal_resource_native_user_selection.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Cel string
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- Resource
Id string - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- Cel string
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- Resource
Id string - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel string
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource_
id string - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel String
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource
Id String - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel string
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource
Id string - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel str
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource_
id str - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
- cel String
- The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
- resource
Id String - The ID of the Resource this selection applies to. Only one selection can exist per Resource.
Package Details
- Repository
- formal formalco/pulumi-formal
- License
- MPL-2.0
- Notes
- This Pulumi package is based on the
formalTerraform Provider.
published on Monday, Sep 21, 2026 by Formal