Skip to main content

AWS CDK constructs for Directory Service Managed AD

Project description

cdk-managed-ad

This is a level 2ish/3 cdk construct library for

Usage

The MicrosoftAD construct creates an AWS Managed Microsoft AD directory in your VPC. Here's how to use it:

import * as cdk from 'aws-cdk-lib';
import * as ec2 from 'aws-cdk-lib/aws-ec2';
import * as sm from 'aws-cdk-lib/aws-secretsmanager';
import { MicrosoftAD } from './microsoft-ad';

const stack = new cdk.Stack();

// Create a VPC (or use an existing one)
const vpc = new ec2.Vpc(stack, 'VPC', {
  maxAzs: 2,
});

// Existing Secret ARN of string type (not JSON)
const EXISTING_SECRET_ARN = string "arn:aws:secretsmanager:YOUR_REGION:YOUR_ACCOUNT_ID:secret:YOUR_EXISTING_SECRET_ARN"

// Create the Microsoft AD
const ad = new MicrosoftAD(stack, 'CorporateAD', {
  domainName: 'corp.example.com',
  password: sm.Secret.fromSecretCompleteArn(self, "ExistingSecret", EXISTING_SECRET_ARN)
  vpc: vpc,
  edition: 'Standard', // or 'Enterprise'
  shortName: 'CORP', // optional. This would be your NetBIOS name.
  enableDirectoryDataAccess: true, // optional, . Enables Directory Service Data Access
});

// The directory ID and DNS IPs are available as properties
console.log('Directory ID:', ad.directoryId);
console.log('DNS IPs:', ad.dnsIps);
console.log('Admin Password Secret ARN:', ad.secretArn);

Properties

  • domainName (required): The fully qualified domain name for the AD directory (e.g., corp.example.com)
  • password (optional): The an AWS Secrets Manager ARN for the directory administrator (if not provided, a secure random password will be generated)
  • vpc (required): VPC where the Microsoft AD will be created (must have at least 2 subnets in different AZs)
  • edition (optional): Edition of Microsoft AD ('Standard' or 'Enterprise', defaults to 'Standard')
  • shortName (optional): Short name for the directory (e.g., CORP)
  • vpcSubnets (optional): Specific subnet selection for the AD (defaults to two subnets from different AZs)
  • enableDirectoryDataAccess (optional) - Deploy custom resource to enable the Directory Service Data API. Default is false. To use this you must add "@aws-cdk/customresources:installLatestAwsSdkDefault": true context to your cdk.json.

Security

See CONTRIBUTING for more information.

License

This library is licensed under the MIT-0 License. See the LICENSE file.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cdk_managed_ad-0.0.4.tar.gz (155.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

cdk_managed_ad-0.0.4-py3-none-any.whl (153.8 kB view details)

Uploaded Python 3

File details

Details for the file cdk_managed_ad-0.0.4.tar.gz.

File metadata

  • Download URL: cdk_managed_ad-0.0.4.tar.gz
  • Upload date:
  • Size: 155.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.0.1 CPython/3.12.8

File hashes

Hashes for cdk_managed_ad-0.0.4.tar.gz
Algorithm Hash digest
SHA256 7297ef37f313bcc1792fc851956e93b57126dee003109e27d3494c4b02c6f064
MD5 45d4a13f5b272ca949216b1ad9c61481
BLAKE2b-256 eceebeb21ffa276636bbc458ed8729d9586a7580a91058c8bdf65513ef930199

See more details on using hashes here.

File details

Details for the file cdk_managed_ad-0.0.4-py3-none-any.whl.

File metadata

  • Download URL: cdk_managed_ad-0.0.4-py3-none-any.whl
  • Upload date:
  • Size: 153.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.0.1 CPython/3.12.8

File hashes

Hashes for cdk_managed_ad-0.0.4-py3-none-any.whl
Algorithm Hash digest
SHA256 6c48fe4c9f6ec96f66b1b62963a04ab9b6dd2c793f30c54035eaf2d88cbfc402
MD5 b416670db16c9d80848701743c33f6af
BLAKE2b-256 b59cd758c6e2c0d0abd0bf2248c37f475a2b4d0348b21c0855db591c75c7ed9b

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page