Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

f/aws_organizations_policy:support for tags #15316

Merged
merged 4 commits into from
Sep 24, 2020
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
21 changes: 21 additions & 0 deletions aws/resource_aws_organizations_policy.go
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,7 @@ import (
"github.com/hashicorp/terraform-plugin-sdk/v2/helper/resource"
"github.com/hashicorp/terraform-plugin-sdk/v2/helper/schema"
"github.com/hashicorp/terraform-plugin-sdk/v2/helper/validation"
"github.com/terraform-providers/terraform-provider-aws/aws/internal/keyvaluetags"
)

func resourceAwsOrganizationsPolicy() *schema.Resource {
Expand Down Expand Up @@ -53,6 +54,7 @@ func resourceAwsOrganizationsPolicy() *schema.Resource {
organizations.PolicyTypeTagPolicy,
}, false),
},
"tags": tagsSchema(),
},
}
}
Expand All @@ -68,6 +70,7 @@ func resourceAwsOrganizationsPolicyCreate(d *schema.ResourceData, meta interface
Description: aws.String(d.Get("description").(string)),
Name: aws.String(d.Get("name").(string)),
Type: aws.String(d.Get("type").(string)),
Tags: keyvaluetags.New(d.Get("tags").(map[string]interface{})).IgnoreAws().OrganizationsTags(),
}

log.Printf("[DEBUG] Creating Organizations Policy: %s", input)
Expand Down Expand Up @@ -103,6 +106,7 @@ func resourceAwsOrganizationsPolicyCreate(d *schema.ResourceData, meta interface

func resourceAwsOrganizationsPolicyRead(d *schema.ResourceData, meta interface{}) error {
conn := meta.(*AWSClient).organizationsconn
ignoreTagsConfig := meta.(*AWSClient).IgnoreTagsConfig

input := &organizations.DescribePolicyInput{
PolicyId: aws.String(d.Id()),
Expand Down Expand Up @@ -130,6 +134,16 @@ func resourceAwsOrganizationsPolicyRead(d *schema.ResourceData, meta interface{}
d.Set("description", resp.Policy.PolicySummary.Description)
d.Set("name", resp.Policy.PolicySummary.Name)
d.Set("type", resp.Policy.PolicySummary.Type)

tags, err := keyvaluetags.OrganizationsListTags(conn, d.Id())
if err != nil {
return fmt.Errorf("error listing tags: %s", err)
}

if err := d.Set("tags", tags.IgnoreAws().IgnoreConfig(ignoreTagsConfig).Map()); err != nil {
return fmt.Errorf("error setting tags: %s", err)
}

return nil
}

Expand Down Expand Up @@ -158,6 +172,13 @@ func resourceAwsOrganizationsPolicyUpdate(d *schema.ResourceData, meta interface
return fmt.Errorf("error updating Organizations Policy: %s", err)
}

if d.HasChange("tags") {
o, n := d.GetChange("tags")
if err := keyvaluetags.OrganizationsUpdateTags(conn, d.Id(), o, n); err != nil {
return fmt.Errorf("error updating tags: %s", err)
}
}

return resourceAwsOrganizationsPolicyRead(d, meta)
}

Expand Down
128 changes: 128 additions & 0 deletions aws/resource_aws_organizations_policy_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -113,6 +113,51 @@ func testAccAwsOrganizationsPolicy_description(t *testing.T) {
})
}

func testAccAwsOrganizationsPolicy_tags(t *testing.T) {
var p1, p2, p3 organizations.Policy
rName := acctest.RandomWithPrefix("tf-acc-test")
resourceName := "aws_organizations_policy.test"

resource.Test(t, resource.TestCase{
PreCheck: func() { testAccPreCheck(t); testAccOrganizationsAccountPreCheck(t) },
Providers: testAccProviders,
CheckDestroy: testAccCheckAwsOrganizationsPolicyDestroy,
Steps: []resource.TestStep{
{
Config: testAccAwsOrganizationsPolicyConfig_TagA(rName),
Check: resource.ComposeTestCheckFunc(
testAccCheckAwsOrganizationsPolicyExists(resourceName, &p1),
resource.TestCheckResourceAttr(resourceName, "tags.%", "2"),
resource.TestCheckResourceAttr(resourceName, "tags.TerraformProviderAwsTest", "true"),
resource.TestCheckResourceAttr(resourceName, "tags.Alpha", "1"),
),
},
{
ResourceName: resourceName,
ImportState: true,
ImportStateVerify: true,
},
{
Config: testAccAwsOrganizationsPolicyConfig_TagB(rName),
Check: resource.ComposeTestCheckFunc(
testAccCheckAwsOrganizationsPolicyExists(resourceName, &p2),
resource.TestCheckResourceAttr(resourceName, "tags.%", "2"),
resource.TestCheckResourceAttr(resourceName, "tags.TerraformProviderAwsTest", "true"),
resource.TestCheckResourceAttr(resourceName, "tags.Beta", "1"),
),
},
{
Config: testAccAwsOrganizationsPolicyConfig_TagC(rName),
Check: resource.ComposeTestCheckFunc(
testAccCheckAwsOrganizationsPolicyExists(resourceName, &p3),
resource.TestCheckResourceAttr(resourceName, "tags.%", "1"),
resource.TestCheckResourceAttr(resourceName, "tags.TerraformProviderAwsTest", "true"),
),
},
nikhil-goenka marked this conversation as resolved.
Show resolved Hide resolved
},
})
}

func testAccAwsOrganizationsPolicy_type_AI_OPT_OUT(t *testing.T) {
var policy organizations.Policy
rName := acctest.RandomWithPrefix("tf-acc-test")
Expand Down Expand Up @@ -383,6 +428,89 @@ EOF
`, description, rName)
}

func testAccAwsOrganizationsPolicyConfig_TagA(rName string) string {
return fmt.Sprintf(`
resource "aws_organizations_organization" "test" {}

resource "aws_organizations_policy" "test" {
content = <<EOF
{
"Version": "2012-10-17",
"Statement": {
"Effect": "Allow",
"Action": "*",
"Resource": "*"
}
}
EOF

name = "%s"

depends_on = [aws_organizations_organization.test]

tags = {
TerraformProviderAwsTest = true
Alpha = 1
}
}
`, rName)
}

func testAccAwsOrganizationsPolicyConfig_TagB(rName string) string {
return fmt.Sprintf(`
resource "aws_organizations_organization" "test" {}

resource "aws_organizations_policy" "test" {
content = <<EOF
{
"Version": "2012-10-17",
"Statement": {
"Effect": "Allow",
"Action": "*",
"Resource": "*"
}
}
EOF

name = "%s"

depends_on = [aws_organizations_organization.test]

tags = {
TerraformProviderAwsTest = true
Beta = 1
}
}
`, rName)
}

func testAccAwsOrganizationsPolicyConfig_TagC(rName string) string {
return fmt.Sprintf(`
resource "aws_organizations_organization" "test" {}

resource "aws_organizations_policy" "test" {
content = <<EOF
{
"Version": "2012-10-17",
"Statement": {
"Effect": "Allow",
"Action": "*",
"Resource": "*"
}
}
EOF

name = "%s"

depends_on = [aws_organizations_organization.test]

tags = {
TerraformProviderAwsTest = true
}
}
`, rName)
}

func testAccAwsOrganizationsPolicyConfig_Required(rName, content string) string {
return fmt.Sprintf(`
resource "aws_organizations_organization" "test" {}
Expand Down