AWS CDK constructs for Directory Service Managed AD
Project description
cdk-managed-ad
This is a level 2ish/3ish cdk construct library for deployment and management of a AWS Managed Microsoft AD.
Usage
The MicrosoftAD construct creates an AWS Managed Microsoft AD directory in your VPC. Here's how to use it:
import * as cdk from 'aws-cdk-lib';
import * as ec2 from 'aws-cdk-lib/aws-ec2';
import * as sm from 'aws-cdk-lib/aws-secretsmanager';
import { MicrosoftAD } from 'cdk-managed-ad';
const stack = new cdk.Stack();
// Create a VPC (or use an existing one)
const vpc = new ec2.Vpc(stack, 'VPC', {
maxAzs: 2,
});
// Existing Secret ARN of password as string (not JSON). Username will be NETBIOS\admin
const EXISTING_SECRET_ARN = string "arn:aws:secretsmanager:YOUR_REGION:YOUR_ACCOUNT_ID:secret:YOUR_EXISTING_SECRET_ARN"
// Create the Microsoft AD
const ad = new MicrosoftAD(stack, 'CorporateAD', {
domainName: 'corp.example.com',
password: sm.Secret.fromSecretCompleteArn(self, "ExistingSecret", EXISTING_SECRET_ARN),
vpc: vpc,
edition: 'Standard', // or 'Enterprise'
shortName: 'CORP', // optional. This would be your NetBIOS name.
enableDirectoryDataAccess: true, // optional, . Enables Directory Service Data Access
});
// The directory ID and DNS IPs are available as properties
console.log('Directory ID:', ad.directoryId);
console.log('DNS IPs:', ad.dnsIps);
console.log('Admin Password Secret ARN:', ad.secretArn);
Properties
domainName(required): The fully qualified domain name for the AD directory (e.g., corp.example.com)password(optional): The an AWS Secrets Manager ARN for the directory administrator (if not provided, a secure random password will be generated)vpc(required): VPC where the Microsoft AD will be created (must have at least 2 subnets in different AZs)edition(optional): Edition of Microsoft AD ('Standard' or 'Enterprise', defaults to 'Standard')shortName(optional): Short name for the directory (e.g., CORP)vpcSubnets(optional): Specific subnet selection for the AD (defaults to two subnets from different AZs)enableDirectoryDataAccess(optional) - Deploy custom resource to enable the Directory Service Data API. Default is false.
Security
See CONTRIBUTING for more information.
License
This library is licensed under the MIT-0 License. See the LICENSE file.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file cdk_managed_ad-0.0.11.tar.gz.
File metadata
- Download URL: cdk_managed_ad-0.0.11.tar.gz
- Upload date:
- Size: 155.2 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.13.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
20b025894ffe948aa4b9cb5ca1a761e0af29ba4f9873e897d22513295a67b328
|
|
| MD5 |
4112744d108db2fb1a92da1e8ddbf951
|
|
| BLAKE2b-256 |
c5a20849876f2441a69dc3854615042ae4e9e26b668a3110184ab43e7d29d688
|
File details
Details for the file cdk_managed_ad-0.0.11-py3-none-any.whl.
File metadata
- Download URL: cdk_managed_ad-0.0.11-py3-none-any.whl
- Upload date:
- Size: 153.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.13.2
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
82175201ae26613192609ab4f25ab9baf3f3169c5518d57c5330df22a3c25b3e
|
|
| MD5 |
a5f6231cfb869b055fc229823dcacafb
|
|
| BLAKE2b-256 |
e72a829a3d5beacd428d498856202f87e025ae0259a57de3f1ffc6579df363a1
|