Skip to content

Creates or updates the authorization policy for a Client VPN endpoint

Description

Creates or updates the authorization policy for a Client VPN endpoint. A Client VPN endpoint can have one authorization policy. If a policy already exists for the endpoint, the values that you specify replace the corresponding values in the existing policy, and values that you do not specify remain unchanged.

Usage

ec2_modify_client_vpn_endpoint_authorization_policy(ClientVpnEndpointId,
  PolicyDocument, Description, ShadowMode, ClientToken, DryRun)

Arguments

  • ClientVpnEndpointId

[required] The ID of the Client VPN endpoint.

  • PolicyDocument

The authorization policy document, written in the Cedar policy language. This parameter is required when you create the authorization policy for a Client VPN endpoint that does not already have one.

  • Description

A brief description of the authorization policy.

  • ShadowMode

Specifies whether the authorization policy is evaluated in shadow mode. Possible values include:

  • enabled - The authorization policy is evaluated and the results are logged, but access is not enforced.
  • disabled - The authorization policy is enforced.

The default value is disabled.

  • ClientToken

Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see Ensuring idempotency.

  • DryRun

Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.

Value

A list with the following syntax:

list(
  Status = "creating"|"updating"|"active"|"failed"|"deleting"
)

Request syntax

svc$modify_client_vpn_endpoint_authorization_policy(
  ClientVpnEndpointId = "string",
  PolicyDocument = "string",
  Description = "string",
  ShadowMode = "enabled"|"disabled",
  ClientToken = "string",
  DryRun = TRUE|FALSE
)