Skip to main content

AWS IoT Thing, Certificate, and Policy Construct Library

NPM PyPI Maven version NuGet version Go version License

---

cdk-constructs: Experimental

The APIs of higher level constructs in this module are experimental and under active development. They are subject to non-backward compatible changes or removal in any future version. These are not subject to the Semantic Versioning model and breaking changes will be announced in the release notes. This means that while you may use them, you may need to update your source code when upgrading to a newer version of this package.


View on Construct Hub

An L3 CDK construct to create and associate a singular AWS IoT Thing, Certificate, and IoT Policy. The construct also retrieves and returns AWS IoT account specific details such as the AWS IoT data endpoint and the AWS IoT Credential provider endpoint.

The certificate and its private key are stored as AWS Systems Manager Parameter Store parameters that can be retrieved via the AWS Console or programmatically via construct members.

Installing

TypeScript/JavaScript

npm install @cdklabs/cdk-aws-iot-thing-certificate-policy

Python

pip install cdklabs.cdk-aws-iot-thing-certificate-policy

Java

// add this to your pom.xml
<dependency>
    <groupId>io.github.cdklabs</groupId>
    <artifactId>cdk-aws-iot-thing-certificate-policy</artifactId>
    <version>0.0.0</version> // replace with version
</dependency>

.NET

dotnet add package Cdklabs.CdkAwsIotThingCertificatePolicy --version X.X.X

Go

// Add this
import "github.com/cdklabs/cdk-aws-iot-thing-certificate-policy-go/cdklabscdkawsiotthingcertificatepolicy"

Usage

from cdklabs.cdk_aws_iot_thing_certificate_policy import PolicyMapping, PolicyMapping
import aws_cdk as cdk
from cdklabs.cdk_aws_iot_thing_certificate_policy import IotThingCertificatePolicy
#
# A minimum IoT Policy template using substitution variables for actual
# policy to be deployed for "region", "account", and "thingname". Allows
# the thing to publish and subscribe on any topics under "thing/*" topic
# namespace. Normal IoT Policy conventions such as "*", apply.
#
minimal_iot_policy = """{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["iot:Connect"],
      "Resource": "arn:aws:iot:{{region}}:{{account}}:client/{{thingname}}"
    },
    {
      "Effect": "Allow",
      "Action": ["iot:Publish"],
      "Resource": [
        "arn:aws:iot:{{region}}:{{account}}:topic/{{thingname}}/*"
      ]
    },
    {
      "Effect": "Allow",
      "Action": ["iot:Subscribe"],
      "Resource": [
        "arn:aws:iot:{{region}}:{{account}}:topicfilter/{{thingname}}/*"
      ]
    },
    {
      "Effect": "Allow",
      "Action": ["iot:Receive"],
      "Resource": [
        "arn:aws:iot:{{region}}:{{account}}:topic/{{thingname}}/*"
      ]
    }
  ]
}"""

app = cdk.App()

#
# Create the thing, certificate, and policy, then associate the
# certificate to both the thing and the policy and fully activate.
#
foo_thing = IotThingCertificatePolicy(app, "MyFooThing",
    thing_name="foo-thing",  # Name to assign to AWS IoT thing, and value for {{thingname}} in policy template
    iot_policy_name="foo-iot-policy",  # Name to assign to AWS IoT policy
    iot_policy=minimal_iot_policy,  # Policy with or without substitution parameters from above
    encryption_algorithm="ECC",  # Algorithm to use to private key (RSA or ECC)
    policy_parameter_mapping=[PolicyMapping(
        name="region",
        value=cdk.Fn.ref("AWS::Region")
    ), PolicyMapping(
        name="account",
        value=cdk.Fn.ref("AWS::AccountId")
    )
    ],
    # Optional: if the X.509 Subject is not provided, a set of default values will be used and the
    # common name (CN) will be set from the thingName parameter.
    x509_subject="CN=foo-thing,OU=Information Security,O=ACME Inc.,L=Detroit,ST=Michigan,C=US"
)

# The AWS IoT Thing Arn as a stack output
cdk.CfnOutput(app, "ThingArn",
    value=foo_thing.thing_arn
)
# The AWS account unique endpoint for the MQTT data connection
# See API for other available public values that can be referenced
cdk.CfnOutput(app, "IotEndpoint",
    value=foo_thing.data_ats_endpoint_address
)

Metadata

Release files for cdklabs.cdk-aws-iot-thing-certificate-policy 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for cdklabs.cdk-aws-iot-thing-certificate-policy 1.0.0
File Size Uploaded
cdklabs_cdk_aws_iot_thing_certificate_policy-1.0.0.tar.gz 1.2 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for cdklabs.cdk-aws-iot-thing-certificate-policy 1.0.0
File Interpreter ABI Platform
cdklabs.cdk_aws_iot_thing_certificate_policy-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 2.5 MB

Release files / cdklabs_cdk_aws_iot_thing_certificate_policy-1.0.0.tar.gz

Download URL cdklabs_cdk_aws_iot_thing_certificate_policy-1.0.0.tar.gz
Size 1.2 MB
Tags Source
SHA-256 checksum
How to use checksums
bdcdbd15a96c90ead9cba7433abf036195354697587ddb5e54908fcb5ce2cbf8
BLAKE2b-256 checksum
How to use checksums
f0729f7f1dd49902b7eb58cf956b4be1894ffa59a76cc8ac53c86d8f2a61e665
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.1.1 CPython/3.12.7

Release files / cdklabs.cdk_aws_iot_thing_certificate_policy-1.0.0-py3-none-any.whl

Download URL cdklabs.cdk_aws_iot_thing_certificate_policy-1.0.0-py3-none-any.whl
Size 1.2 MB
Tags Python 3
SHA-256 checksum
How to use checksums
4a04b75905b60ea518bfd4c486477edaa9fe27582cd3e5eb1ee1b85242a91ef5
BLAKE2b-256 checksum
How to use checksums
e4138b2b28d446fdf44556fe8d9351025d19767ac66400c10a2d3b66b9cc8859
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/5.1.1 CPython/3.12.7

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

0.0.9

2 release files

0.0.8

2 release files

0.0.7

2 release files

0.0.6

2 release files

0.0.5

2 release files

0.0.4

2 release files

0.0.3

2 release files

0.0.2

2 release files

0.0.1

2 release files

0.0.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page