1. Registry
  2. Packages
  3. Formal Provider
  4. API Docs
  5. ResourceNativeUserSelection
Viewing docs for Formal v1.2.7
published on Monday, Sep 21, 2026 by Formal
formal logo
Viewing docs for Formal v1.2.7
published on Monday, Sep 21, 2026 by Formal

    Controls which Native User V3 a session connects to a Resource as using a CEL expression. Enable Native Users V3 on the Resource separately with nativeUsersV3Enabled.

    Example Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as formal from "@formalco/pulumi";
    
    const db = new formal.Resource("db", {
        name: "analytics-postgres",
        hostname: "analytics.internal",
        technology: "postgres",
        port: 5432,
        nativeUsersV3Enabled: true,
    });
    const admin = new formal.NativeUserV3("admin", {
        basic: {
            password: {
                environmentVariable: "ANALYTICS_ADMIN_PASSWORD",
            },
            username: "app_admin",
        },
        resourceId: db.id,
        label: "admin",
    });
    const readOnly = new formal.NativeUserV3("read_only", {
        basic: {
            password: {
                environmentVariable: "ANALYTICS_READONLY_PASSWORD",
            },
            username: "app_readonly",
        },
        resourceId: db.id,
        label: "read-only",
    });
    // Sessions from the admins group connect as app_admin; everyone else connects as
    // app_readonly.
    const dbResourceNativeUserSelection = new formal.ResourceNativeUserSelection("db", {
        resourceId: db.id,
        cel: pulumi.interpolate`\"admins\" in user.groups ? \"${admin.id}\"
    : \"${readOnly.id}\"
    `,
    });
    
    import pulumi
    import pulumi_formal as formal
    
    db = formal.Resource("db",
        name="analytics-postgres",
        hostname="analytics.internal",
        technology="postgres",
        port=5432,
        native_users_v3_enabled=True)
    admin = formal.NativeUserV3("admin",
        basic={
            "password": {
                "environment_variable": "ANALYTICS_ADMIN_PASSWORD",
            },
            "username": "app_admin",
        },
        resource_id=db.id,
        label="admin")
    read_only = formal.NativeUserV3("read_only",
        basic={
            "password": {
                "environment_variable": "ANALYTICS_READONLY_PASSWORD",
            },
            "username": "app_readonly",
        },
        resource_id=db.id,
        label="read-only")
    # Sessions from the admins group connect as app_admin; everyone else connects as
    # app_readonly.
    db_resource_native_user_selection = formal.ResourceNativeUserSelection("db",
        resource_id=db.id,
        cel=pulumi.Output.all(
            adminId=admin.id,
            readOnlyId=read_only.id
    ).apply(lambda resolved_outputs: f"""\"admins\" in user.groups ? \"{resolved_outputs['adminId']}\"
    : \"{resolved_outputs['readOnlyId']}\"
    """)
    )
    
    package main
    
    import (
    	"fmt"
    
    	"github.com/formalco/pulumi-formal/sdk/go/formal"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		db, err := formal.NewResource(ctx, "db", &formal.ResourceArgs{
    			Name:                 pulumi.String("analytics-postgres"),
    			Hostname:             pulumi.String("analytics.internal"),
    			Technology:           pulumi.String("postgres"),
    			Port:                 pulumi.Int(5432),
    			NativeUsersV3Enabled: pulumi.Bool(true),
    		})
    		if err != nil {
    			return err
    		}
    		admin, err := formal.NewNativeUserV3(ctx, "admin", &formal.NativeUserV3Args{
    			Basic: &formal.NativeUserV3BasicArgs{
    				Password: &formal.NativeUserV3BasicPasswordArgs{
    					EnvironmentVariable: pulumi.String("ANALYTICS_ADMIN_PASSWORD"),
    				},
    				Username: pulumi.String("app_admin"),
    			},
    			ResourceId: db.ID(),
    			Label:      pulumi.String("admin"),
    		})
    		if err != nil {
    			return err
    		}
    		readOnly, err := formal.NewNativeUserV3(ctx, "read_only", &formal.NativeUserV3Args{
    			Basic: &formal.NativeUserV3BasicArgs{
    				Password: &formal.NativeUserV3BasicPasswordArgs{
    					EnvironmentVariable: pulumi.String("ANALYTICS_READONLY_PASSWORD"),
    				},
    				Username: pulumi.String("app_readonly"),
    			},
    			ResourceId: db.ID(),
    			Label:      pulumi.String("read-only"),
    		})
    		if err != nil {
    			return err
    		}
    		// Sessions from the admins group connect as app_admin; everyone else connects as
    		// app_readonly.
    		_, err = formal.NewResourceNativeUserSelection(ctx, "db", &formal.ResourceNativeUserSelectionArgs{
    			ResourceId: db.ID(),
    			Cel: pulumi.All(admin.ID(), readOnly.ID()).ApplyT(func(_args []interface{}) (string, error) {
    				adminId := _args[0].(string)
    				readOnlyId := _args[1].(string)
    				return fmt.Sprintf("\\\"admins\\\" in user.groups ? \\\"%v\\\"\n: \\\"%v\\\"\n", adminId, readOnlyId), nil
    			}).(pulumi.StringOutput),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Pulumi = Formal.Pulumi;
    
    return await Deployment.RunAsync(() => 
    {
        var db = new Pulumi.Resource("db", new()
        {
            Name = "analytics-postgres",
            Hostname = "analytics.internal",
            Technology = "postgres",
            Port = 5432,
            NativeUsersV3Enabled = true,
        });
    
        var admin = new Pulumi.NativeUserV3("admin", new()
        {
            Basic = new Pulumi.Inputs.NativeUserV3BasicArgs
            {
                Password = new Pulumi.Inputs.NativeUserV3BasicPasswordArgs
                {
                    EnvironmentVariable = "ANALYTICS_ADMIN_PASSWORD",
                },
                Username = "app_admin",
            },
            ResourceId = db.Id,
            Label = "admin",
        });
    
        var readOnly = new Pulumi.NativeUserV3("read_only", new()
        {
            Basic = new Pulumi.Inputs.NativeUserV3BasicArgs
            {
                Password = new Pulumi.Inputs.NativeUserV3BasicPasswordArgs
                {
                    EnvironmentVariable = "ANALYTICS_READONLY_PASSWORD",
                },
                Username = "app_readonly",
            },
            ResourceId = db.Id,
            Label = "read-only",
        });
    
        // Sessions from the admins group connect as app_admin; everyone else connects as
        // app_readonly.
        var dbResourceNativeUserSelection = new Pulumi.ResourceNativeUserSelection("db", new()
        {
            ResourceId = db.Id,
            Cel = Output.Tuple(admin.Id, readOnly.Id).Apply(values =>
            {
                var adminId = values.Item1;
                var readOnlyId = values.Item2;
                return @$"\""admins\"" in user.groups ? \""{adminId}\""
    : \""{readOnlyId}\""
    ";
            }),
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.formal.Resource;
    import com.pulumi.formal.ResourceArgs;
    import com.pulumi.formal.NativeUserV3;
    import com.pulumi.formal.NativeUserV3Args;
    import com.pulumi.formal.inputs.NativeUserV3BasicArgs;
    import com.pulumi.formal.inputs.NativeUserV3BasicPasswordArgs;
    import com.pulumi.formal.ResourceNativeUserSelection;
    import com.pulumi.formal.ResourceNativeUserSelectionArgs;
    import java.util.ArrayList;
    import java.util.Arrays;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var db = new Resource("db", ResourceArgs.builder()
                .name("analytics-postgres")
                .hostname("analytics.internal")
                .technology("postgres")
                .port(5432)
                .nativeUsersV3Enabled(true)
                .build());
    
            var admin = new NativeUserV3("admin", NativeUserV3Args.builder()
                .basic(NativeUserV3BasicArgs.builder()
                    .password(NativeUserV3BasicPasswordArgs.builder()
                        .environmentVariable("ANALYTICS_ADMIN_PASSWORD")
                        .build())
                    .username("app_admin")
                    .build())
                .resourceId(db.id())
                .label("admin")
                .build());
    
            var readOnly = new NativeUserV3("readOnly", NativeUserV3Args.builder()
                .basic(NativeUserV3BasicArgs.builder()
                    .password(NativeUserV3BasicPasswordArgs.builder()
                        .environmentVariable("ANALYTICS_READONLY_PASSWORD")
                        .build())
                    .username("app_readonly")
                    .build())
                .resourceId(db.id())
                .label("read-only")
                .build());
    
            // Sessions from the admins group connect as app_admin; everyone else connects as
            // app_readonly.
            var dbResourceNativeUserSelection = new ResourceNativeUserSelection("dbResourceNativeUserSelection", ResourceNativeUserSelectionArgs.builder()
                .resourceId(db.id())
                .cel(Output.tuple(admin.id(), readOnly.id()).applyValue(values -> {
                    var adminId = values.t1;
                    var readOnlyId = values.t2;
                    return """
    \"admins\" in user.groups ? \"%s\"
    : \"%s\"
    ", adminId,readOnlyId);
                }))
                .build());
    
        }
    }
    
    resources:
      db:
        type: formal:Resource
        properties:
          name: analytics-postgres
          hostname: analytics.internal
          technology: postgres
          port: 5432
          nativeUsersV3Enabled: true
      admin:
        type: formal:NativeUserV3
        properties:
          basic:
            password:
              environmentVariable: ANALYTICS_ADMIN_PASSWORD
            username: app_admin
          resourceId: ${db.id}
          label: admin
      readOnly:
        type: formal:NativeUserV3
        name: read_only
        properties:
          basic:
            password:
              environmentVariable: ANALYTICS_READONLY_PASSWORD
            username: app_readonly
          resourceId: ${db.id}
          label: read-only
      # Sessions from the admins group connect as app_admin; everyone else connects as
      # app_readonly.
      dbResourceNativeUserSelection:
        type: formal:ResourceNativeUserSelection
        name: db
        properties:
          resourceId: ${db.id}
          cel: |
            \"admins\" in user.groups ? \"${admin.id}\"
            : \"${readOnly.id}\"
    
    pulumi {
      required_providers {
        formal = {
          source = "pulumi/formal"
        }
      }
    }
    
    resource "formal_resource" "db" {
      name                    = "analytics-postgres"
      hostname                = "analytics.internal"
      technology              = "postgres"
      port                    = 5432
      native_users_v3_enabled = true
    }
    resource "formal_nativeuserv3" "admin" {
      basic = {
        password = {
          environment_variable = "ANALYTICS_ADMIN_PASSWORD"
        }
        username = "app_admin"
      }
      resource_id = formal_resource.db.id
      label       = "admin"
    }
    resource "formal_nativeuserv3" "read_only" {
      basic = {
        password = {
          environment_variable = "ANALYTICS_READONLY_PASSWORD"
        }
        username = "app_readonly"
      }
      resource_id = formal_resource.db.id
      label       = "read-only"
    }
    # Sessions from the admins group connect as app_admin; everyone else connects as
    # app_readonly.
    resource "formal_resourcenativeuserselection" "db" {
      resource_id = formal_resource.db.id
      cel         ="\"admins\" in user.groups ? \"${formal_nativeuserv3.admin.id}\"
    : \"${formal_nativeuserv3.read_only.id}\"
    "
    }
    

    Create ResourceNativeUserSelection Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new ResourceNativeUserSelection(name: string, args: ResourceNativeUserSelectionArgs, opts?: CustomResourceOptions);
    @overload
    def ResourceNativeUserSelection(resource_name: str,
                                    args: ResourceNativeUserSelectionArgs,
                                    opts: Optional[ResourceOptions] = None)
    
    @overload
    def ResourceNativeUserSelection(resource_name: str,
                                    opts: Optional[ResourceOptions] = None,
                                    cel: Optional[str] = None,
                                    resource_id: Optional[str] = None)
    func NewResourceNativeUserSelection(ctx *Context, name string, args ResourceNativeUserSelectionArgs, opts ...ResourceOption) (*ResourceNativeUserSelection, error)
    public ResourceNativeUserSelection(string name, ResourceNativeUserSelectionArgs args, CustomResourceOptions? opts = null)
    public ResourceNativeUserSelection(String name, ResourceNativeUserSelectionArgs args)
    public ResourceNativeUserSelection(String name, ResourceNativeUserSelectionArgs args, CustomResourceOptions options)
    
    type: formal:ResourceNativeUserSelection
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "formal_resource_native_user_selection" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args ResourceNativeUserSelectionArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args ResourceNativeUserSelectionArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args ResourceNativeUserSelectionArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args ResourceNativeUserSelectionArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args ResourceNativeUserSelectionArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var resourceNativeUserSelectionResource = new Pulumi.ResourceNativeUserSelection("resourceNativeUserSelectionResource", new()
    {
        Cel = "string",
        ResourceId = "string",
    });
    
    example, err := formal.NewResourceNativeUserSelection(ctx, "resourceNativeUserSelectionResource", &formal.ResourceNativeUserSelectionArgs{
    	Cel:        pulumi.String("string"),
    	ResourceId: pulumi.String("string"),
    })
    
    resource "formal_resource_native_user_selection" "resourceNativeUserSelectionResource" {
      lifecycle {
        create_before_destroy = true
      }
      cel         = "string"
      resource_id = "string"
    }
    
    var resourceNativeUserSelectionResource = new ResourceNativeUserSelection("resourceNativeUserSelectionResource", ResourceNativeUserSelectionArgs.builder()
        .cel("string")
        .resourceId("string")
        .build());
    
    resource_native_user_selection_resource = formal.ResourceNativeUserSelection("resourceNativeUserSelectionResource",
        cel="string",
        resource_id="string")
    
    const resourceNativeUserSelectionResource = new formal.ResourceNativeUserSelection("resourceNativeUserSelectionResource", {
        cel: "string",
        resourceId: "string",
    });
    
    type: formal:ResourceNativeUserSelection
    properties:
        cel: string
        resourceId: string
    

    ResourceNativeUserSelection Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The ResourceNativeUserSelection resource accepts the following input properties:

    Cel string
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    ResourceId string
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    Cel string
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    ResourceId string
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel string
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resource_id string
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel String
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resourceId String
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel string
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resourceId string
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel str
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resource_id str
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel String
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resourceId String
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the ResourceNativeUserSelection resource produces the following output properties:

    Id string
    The provider-assigned unique ID for this managed resource.
    Id string
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id str
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.

    Look up Existing ResourceNativeUserSelection Resource

    Get an existing ResourceNativeUserSelection resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: ResourceNativeUserSelectionState, opts?: CustomResourceOptions): ResourceNativeUserSelection
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            cel: Optional[str] = None,
            resource_id: Optional[str] = None) -> ResourceNativeUserSelection
    func GetResourceNativeUserSelection(ctx *Context, name string, id IDInput, state *ResourceNativeUserSelectionState, opts ...ResourceOption) (*ResourceNativeUserSelection, error)
    public static ResourceNativeUserSelection Get(string name, Input<string> id, ResourceNativeUserSelectionState? state, CustomResourceOptions? opts = null)
    public static ResourceNativeUserSelection get(String name, Output<String> id, ResourceNativeUserSelectionState state, CustomResourceOptions options)
    resources:  _:    type: formal:ResourceNativeUserSelection    get:      id: ${id}
    import {
      to = formal_resource_native_user_selection.example
      id = "${id}"
    }
    
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    Cel string
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    ResourceId string
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    Cel string
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    ResourceId string
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel string
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resource_id string
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel String
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resourceId String
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel string
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resourceId string
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel str
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resource_id str
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.
    cel String
    The CEL expression that returns the ID of the Native User a session connects as, or an empty string to refuse the session.
    resourceId String
    The ID of the Resource this selection applies to. Only one selection can exist per Resource.

    Package Details

    Repository
    formal formalco/pulumi-formal
    License
    MPL-2.0
    Notes
    This Pulumi package is based on the formal Terraform Provider.
    formal logo
    Viewing docs for Formal v1.2.7
    published on Monday, Sep 21, 2026 by Formal

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial