Package com.pulumi.cloudamqp
Class VpcConnect
- java.lang.Object
-
- com.pulumi.resources.Resource
-
- com.pulumi.resources.CustomResource
-
- com.pulumi.cloudamqp.VpcConnect
-
public class VpcConnect extends com.pulumi.resources.CustomResourceThis resource is a generic way to handle PrivateLink (AWS and Azure) and Private Service Connect (GCP). Communication between resources can be done just as they were living inside a VPC. CloudAMQP creates an Endpoint Service to connect the VPC and creating a new network interface to handle the communicate. If no existing VPC available when enable VPC connect, a new VPC will be created with subnet `10.52.72.0/24`. More information can be found at: [CloudAMQP VPC Connect](https://www.cloudamqp.com/docs/cloudamqp-vpc-connect.html) > **Note:** Enabling VPC Connect will automatically add a firewall rule. <details> <summary> <b> <i>Default PrivateLink firewall rule [AWS, Azure]</i> </b> </summary> ```java package generated_program; import com.pulumi.Context; import com.pulumi.Pulumi; import com.pulumi.core.Output; import java.util.List; import java.util.ArrayList; import java.util.Map; import java.io.File; import java.nio.file.Files; import java.nio.file.Paths; public class App { public static void main(String[] args) { Pulumi.run(App::stack); } public static void stack(Context ctx) { } } ``` </details> <details> <summary> <b> <i>Default Private Service Connect firewall rule [GCP]</i> </b> </summary> ```java package generated_program; import com.pulumi.Context; import com.pulumi.Pulumi; import com.pulumi.core.Output; import java.util.List; import java.util.ArrayList; import java.util.Map; import java.io.File; import java.nio.file.Files; import java.nio.file.Paths; public class App { public static void main(String[] args) { Pulumi.run(App::stack); } public static void stack(Context ctx) { } } ``` </details> Only available for dedicated subscription plans. ## Example Usage <details> <summary> <b> <i>Enable VPC Connect (PrivateLink) in AWS</i> </b> </summary> ```java package generated_program; import com.pulumi.Context; import com.pulumi.Pulumi; import com.pulumi.core.Output; import com.pulumi.cloudamqp.Vpc; import com.pulumi.cloudamqp.VpcArgs; import com.pulumi.cloudamqp.Instance; import com.pulumi.cloudamqp.InstanceArgs; import com.pulumi.cloudamqp.VpcConnect; import com.pulumi.cloudamqp.VpcConnectArgs; import java.util.List; import java.util.ArrayList; import java.util.Map; import java.io.File; import java.nio.file.Files; import java.nio.file.Paths; public class App { public static void main(String[] args) { Pulumi.run(App::stack); } public static void stack(Context ctx) { var vpc = new Vpc("vpc", VpcArgs.builder() .region("amazon-web-services::us-west-1") .subnet("10.56.72.0/24") .tags() .build()); var instance = new Instance("instance", InstanceArgs.builder() .plan("bunny-1") .region("amazon-web-services::us-west-1") .tags() .vpcId(vpc.id()) .keepAssociatedVpc(true) .build()); var vpcConnect = new VpcConnect("vpcConnect", VpcConnectArgs.builder() .instanceId(instance.id()) .region(instance.region()) .allowedPrincipals("arn:aws:iam::aws-account-id:user/user-name") .build()); } } ``` </details> <details> <summary> <b> <i>Enable VPC Connect (PrivateLink) in Azure</i> </b> </summary> ```java package generated_program; import com.pulumi.Context; import com.pulumi.Pulumi; import com.pulumi.core.Output; import com.pulumi.cloudamqp.Vpc; import com.pulumi.cloudamqp.VpcArgs; import com.pulumi.cloudamqp.Instance; import com.pulumi.cloudamqp.InstanceArgs; import com.pulumi.cloudamqp.VpcConnect; import com.pulumi.cloudamqp.VpcConnectArgs; import java.util.List; import java.util.ArrayList; import java.util.Map; import java.io.File; import java.nio.file.Files; import java.nio.file.Paths; public class App { public static void main(String[] args) { Pulumi.run(App::stack); } public static void stack(Context ctx) { var vpc = new Vpc("vpc", VpcArgs.builder() .region("azure-arm::westus") .subnet("10.56.72.0/24") .tags() .build()); var instance = new Instance("instance", InstanceArgs.builder() .plan("bunny-1") .region("azure-arm::westus") .tags() .vpcId(vpc.id()) .keepAssociatedVpc(true) .build()); var vpcConnect = new VpcConnect("vpcConnect", VpcConnectArgs.builder() .instanceId(instance.id()) .region(instance.region()) .approvedSubscriptions("XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX") .build()); } } ``` </details> <details> <summary> <b> <i>Enable VPC Connect (Private Service Connect) in GCP</i> </b> </summary> ```java package generated_program; import com.pulumi.Context; import com.pulumi.Pulumi; import com.pulumi.core.Output; import com.pulumi.cloudamqp.Vpc; import com.pulumi.cloudamqp.VpcArgs; import com.pulumi.cloudamqp.Instance; import com.pulumi.cloudamqp.InstanceArgs; import com.pulumi.cloudamqp.VpcConnect; import com.pulumi.cloudamqp.VpcConnectArgs; import java.util.List; import java.util.ArrayList; import java.util.Map; import java.io.File; import java.nio.file.Files; import java.nio.file.Paths; public class App { public static void main(String[] args) { Pulumi.run(App::stack); } public static void stack(Context ctx) { var vpc = new Vpc("vpc", VpcArgs.builder() .region("google-compute-engine::us-west1") .subnet("10.56.72.0/24") .tags() .build()); var instance = new Instance("instance", InstanceArgs.builder() .plan("bunny-1") .region("google-compute-engine::us-west1") .tags() .vpcId(vpc.id()) .keepAssociatedVpc(true) .build()); var vpcConnect = new VpcConnect("vpcConnect", VpcConnectArgs.builder() .instanceId(instance.id()) .region(instance.region()) .allowedProjects("some-project-123456") .build()); } } ``` </details> ### With Additional Firewall Rules <details> <summary> <b> <i>CloudAMQP instance in an existing VPC with managed firewall rules</i> </b> </summary> ```java package generated_program; import com.pulumi.Context; import com.pulumi.Pulumi; import com.pulumi.core.Output; import com.pulumi.cloudamqp.Vpc; import com.pulumi.cloudamqp.VpcArgs; import com.pulumi.cloudamqp.Instance; import com.pulumi.cloudamqp.InstanceArgs; import com.pulumi.cloudamqp.VpcConnect; import com.pulumi.cloudamqp.VpcConnectArgs; import com.pulumi.cloudamqp.SecurityFirewall; import com.pulumi.cloudamqp.SecurityFirewallArgs; import com.pulumi.cloudamqp.inputs.SecurityFirewallRuleArgs; import com.pulumi.resources.CustomResourceOptions; import java.util.List; import java.util.ArrayList; import java.util.Map; import java.io.File; import java.nio.file.Files; import java.nio.file.Paths; public class App { public static void main(String[] args) { Pulumi.run(App::stack); } public static void stack(Context ctx) { var vpc = new Vpc("vpc", VpcArgs.builder() .region("amazon-web-services::us-west-1") .subnet("10.56.72.0/24") .tags() .build()); var instance = new Instance("instance", InstanceArgs.builder() .plan("bunny-1") .region("amazon-web-services::us-west-1") .tags() .vpcId(vpc.id()) .keepAssociatedVpc(true) .build()); var vpcConnect = new VpcConnect("vpcConnect", VpcConnectArgs.builder() .instanceId(instance.id()) .allowedPrincipals("arn:aws:iam::aws-account-id:user/user-name") .build()); var firewallSettings = new SecurityFirewall("firewallSettings", SecurityFirewallArgs.builder() .instanceId(instance.id()) .rules( SecurityFirewallRuleArgs.builder() .description("Custom PrivateLink setup") .ip(vpc.subnet()) .ports() .services( "AMQP", "AMQPS", "HTTPS", "STREAM", "STREAM_SSL") .build(), SecurityFirewallRuleArgs.builder() .description("MGMT interface") .ip("0.0.0.0/0") .ports() .services("HTTPS") .build()) .build(), CustomResourceOptions.builder() .dependsOn(vpcConnect) .build()); } } ``` </details> ## Depedency This resource depends on CloudAMQP instance identifier, `cloudamqp_instance.instance.id`. Since `region` also is required, suggest to reuse the argument from CloudAMQP instance, `cloudamqp_instance.instance.region`. ## Create VPC Connect with additional firewall rules To create a PrivateLink/Private Service Connect configuration with additional firewall rules, it's required to chain the cloudamqp.SecurityFirewall resource to avoid parallel conflicting resource calls. You can do this by making the firewall resource depend on the VPC Connect resource, `cloudamqp_vpc_connect.vpc_connect`. Furthermore, since all firewall rules are overwritten, the otherwise automatically added rules for the VPC Connect also needs to be added. ## Import `cloudamqp_vpc_connect` can be imported using CloudAMQP internal identifier. ```sh $ pulumi import cloudamqp:index/vpcConnect:VpcConnect vpc_connect <id>` ``` The resource uses the same identifier as the CloudAMQP instance. To retrieve the identifier for an instance, either use [CloudAMQP customer API](https://docs.cloudamqp.com/#list-instances) or use the data source [`cloudamqp_account`](./data-sources/account.md).
-
-
Constructor Summary
Constructors Constructor Description VpcConnect(java.lang.String name)VpcConnect(java.lang.String name, VpcConnectArgs args)VpcConnect(java.lang.String name, VpcConnectArgs args, com.pulumi.resources.CustomResourceOptions options)
-
Method Summary
All Methods Static Methods Instance Methods Concrete Methods Modifier and Type Method Description com.pulumi.core.Output<java.util.List<java.lang.String>>activeZones()com.pulumi.core.Output<java.util.Optional<java.util.List<java.lang.String>>>allowedPrincipals()com.pulumi.core.Output<java.util.Optional<java.util.List<java.lang.String>>>allowedProjects()com.pulumi.core.Output<java.util.Optional<java.util.List<java.lang.String>>>approvedSubscriptions()static VpcConnectget(java.lang.String name, com.pulumi.core.Output<java.lang.String> id, VpcConnectState state, com.pulumi.resources.CustomResourceOptions options)Get an existing Host resource's state with the given name, ID, and optional extra properties used to qualify the lookup.com.pulumi.core.Output<java.lang.Integer>instanceId()com.pulumi.core.Output<java.lang.String>region()com.pulumi.core.Output<java.lang.String>serviceName()com.pulumi.core.Output<java.util.Optional<java.lang.Integer>>sleep()com.pulumi.core.Output<java.lang.String>status()com.pulumi.core.Output<java.util.Optional<java.lang.Integer>>timeout()
-
-
-
Constructor Detail
-
VpcConnect
public VpcConnect(java.lang.String name)
- Parameters:
name- The _unique_ name of the resulting resource.
-
VpcConnect
public VpcConnect(java.lang.String name, VpcConnectArgs args)- Parameters:
name- The _unique_ name of the resulting resource.args- The arguments to use to populate this resource's properties.
-
VpcConnect
public VpcConnect(java.lang.String name, VpcConnectArgs args, @Nullable com.pulumi.resources.CustomResourceOptions options)- Parameters:
name- The _unique_ name of the resulting resource.args- The arguments to use to populate this resource's properties.options- A bag of options that control this resource's behavior.
-
-
Method Detail
-
activeZones
public com.pulumi.core.Output<java.util.List<java.lang.String>> activeZones()
- Returns:
- Covering availability zones used when creating an endpoint from other VPC. (AWS)
-
allowedPrincipals
public com.pulumi.core.Output<java.util.Optional<java.util.List<java.lang.String>>> allowedPrincipals()
- Returns:
- List of allowed prinicpals used by AWS, see below table.
-
allowedProjects
public com.pulumi.core.Output<java.util.Optional<java.util.List<java.lang.String>>> allowedProjects()
- Returns:
- List of allowed projects used by GCP, see below table.
-
approvedSubscriptions
public com.pulumi.core.Output<java.util.Optional<java.util.List<java.lang.String>>> approvedSubscriptions()
- Returns:
- List of approved subscriptions used by Azure, see below table.
-
instanceId
public com.pulumi.core.Output<java.lang.Integer> instanceId()
- Returns:
- The CloudAMQP instance identifier.
-
region
public com.pulumi.core.Output<java.lang.String> region()
- Returns:
- The region where the CloudAMQP instance is hosted.
-
serviceName
public com.pulumi.core.Output<java.lang.String> serviceName()
- Returns:
- Service name (alias for Azure) of the PrivateLink.
-
sleep
public com.pulumi.core.Output<java.util.Optional<java.lang.Integer>> sleep()
- Returns:
- Configurable sleep time (seconds) when enable Private Service Connect. Default set to 10 seconds.
-
status
public com.pulumi.core.Output<java.lang.String> status()
- Returns:
- Private Service Connect status [enable, pending, disable]
-
timeout
public com.pulumi.core.Output<java.util.Optional<java.lang.Integer>> timeout()
- Returns:
- Configurable timeout time (seconds) when enable Private Service Connect. Default set to 1800 seconds. *** The `allowed_principals`, `approved_subscriptions` or `allowed_projects` data depends on the provider platform: | Platform | Description | Format | |----------|---------------------|------------------------------------------------------------------------------------------------------------------------------------| | AWS | IAM ARN principals | arn:aws:iam::aws-account-id:root<br /> arn:aws:iam::aws-account-id:user/user-name<br /> arn:aws:iam::aws-account-id:role/role-name | | Azure | Subscription (GUID) | XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX | | GCP | Project IDs* | 6 to 30 lowercase letters, digits, or hyphens | *https://cloud.google.com/resource-manager/reference/rest/v1/projects
-
get
public static VpcConnect get(java.lang.String name, com.pulumi.core.Output<java.lang.String> id, @Nullable VpcConnectState state, @Nullable com.pulumi.resources.CustomResourceOptions options)
Get an existing Host resource's state with the given name, ID, and optional extra properties used to qualify the lookup.- Parameters:
name- The _unique_ name of the resulting resource.id- The _unique_ provider ID of the resource to lookup.state-options- Optional settings to control the behavior of the CustomResource.
-
-