Creates or updates the authorization policy for a Client VPN endpoint¶
Description¶
Creates or updates the authorization policy for a Client VPN endpoint. A Client VPN endpoint can have one authorization policy. If a policy already exists for the endpoint, the values that you specify replace the corresponding values in the existing policy, and values that you do not specify remain unchanged.
Usage¶
ec2_modify_client_vpn_endpoint_authorization_policy(ClientVpnEndpointId,
PolicyDocument, Description, ShadowMode, ClientToken, DryRun)
Arguments¶
ClientVpnEndpointId
[required] The ID of the Client VPN endpoint.
PolicyDocument
The authorization policy document, written in the Cedar policy language. This parameter is required when you create the authorization policy for a Client VPN endpoint that does not already have one.
Description
A brief description of the authorization policy.
ShadowMode
Specifies whether the authorization policy is evaluated in shadow mode. Possible values include:
enabled- The authorization policy is evaluated and the results are logged, but access is not enforced.disabled- The authorization policy is enforced.
The default value is disabled.
ClientToken
Unique, case-sensitive identifier that you provide to ensure the idempotency of the request. For more information, see Ensuring idempotency.
DryRun
Checks whether you have the required permissions for the action, without actually making the request, and provides an error response. If you have the required permissions, the error response is DryRunOperation. Otherwise, it is UnauthorizedOperation.
Value¶
A list with the following syntax: