Skip to content


d/aws_prefix_list: add managed prefix list support
Browse files Browse the repository at this point in the history
  • Loading branch information
roberth-k committed Jul 21, 2020
1 parent e46e4e4 commit ccd00bf
Show file tree
Hide file tree
Showing 3 changed files with 158 additions and 6 deletions.
55 changes: 52 additions & 3 deletions aws/data_source_aws_prefix_list.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,6 +8,8 @@ import (


func dataSourceAwsPrefixList() *schema.Resource {
Expand All @@ -30,16 +32,34 @@ func dataSourceAwsPrefixList() *schema.Resource {
Elem: &schema.Schema{Type: schema.TypeString},
"filter": dataSourceFiltersSchema(),
"owner_id": {
Type: schema.TypeString,
Computed: true,
"address_family": {
Type: schema.TypeString,
Computed: true,
"arn": {
Type: schema.TypeString,
Computed: true,
"max_entries": {
Type: schema.TypeInt,
Computed: true,
"tags": tagsSchemaComputed(),

func dataSourceAwsPrefixListRead(d *schema.ResourceData, meta interface{}) error {
conn := meta.(*AWSClient).ec2conn
ignoreTagsConfig := meta.(*AWSClient).IgnoreTagsConfig

filters, filtersOk := d.GetOk("filter")

req := &ec2.DescribePrefixListsInput{}
req := &ec2.DescribeManagedPrefixListsInput{}
if filtersOk {
req.Filters = buildAwsDataSourceFilters(filters.(*schema.Set))
Expand All @@ -54,7 +74,7 @@ func dataSourceAwsPrefixListRead(d *schema.ResourceData, meta interface{}) error

log.Printf("[DEBUG] Reading Prefix List: %s", req)
resp, err := conn.DescribePrefixLists(req)
resp, err := conn.DescribeManagedPrefixLists(req)
switch {
case err != nil:
return err
Expand All @@ -69,11 +89,40 @@ func dataSourceAwsPrefixListRead(d *schema.ResourceData, meta interface{}) error
d.Set("name", pl.PrefixListName)

cidrs := aws.StringValueSlice(pl.Cidrs)
getEntriesInput := ec2.GetManagedPrefixListEntriesInput{
PrefixListId: pl.PrefixListId,

cidrs := []string(nil)

err = conn.GetManagedPrefixListEntriesPages(
&getEntriesInput, func(output *ec2.GetManagedPrefixListEntriesOutput, last bool) bool {
for _, entry := range output.Entries {
cidrs = append(cidrs, aws.StringValue(entry.Cidr))
return true
if err != nil {
return fmt.Errorf("failed to get entries of prefix list %s: %s", *pl.PrefixListId, err)


if err := d.Set("cidr_blocks", cidrs); err != nil {
return fmt.Errorf("failed to set cidr blocks of prefix list %s: %s", d.Id(), err)

d.Set("owner_id", pl.OwnerId)
d.Set("address_family", pl.AddressFamily)
d.Set("arn", pl.PrefixListArn)

if actual := aws.Int64Value(pl.MaxEntries); actual > 0 {
d.Set("max_entries", actual)

if err := d.Set("tags", keyvaluetags.Ec2KeyValueTags(pl.Tags).IgnoreAws().IgnoreConfig(ignoreTagsConfig).Map()); err != nil {
return fmt.Errorf("failed to set tags of prefix list %s: %s", d.Id(), err)

return nil
74 changes: 74 additions & 0 deletions aws/data_source_aws_prefix_list_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,26 @@ func testAccDataSourceAwsPrefixListCheck(name string) resource.TestCheckFunc {
return fmt.Errorf("cidr_blocks seem suspiciously low: %d", cidrBlockSize)

if actual := attr["owner_id"]; actual != "AWS" {
return fmt.Errorf("bad owner_id %s", actual)

if actual := attr["address_family"]; actual != "IPv4" {
return fmt.Errorf("bad address_family %s", actual)

if actual := attr["arn"]; actual != "arn:aws:ec2:us-west-2:aws:prefix-list/pl-68a54001" {
return fmt.Errorf("bad arn %s", actual)

if actual := attr["max_entries"]; actual != "" {
return fmt.Errorf("unexpected max_entries %s", actual)

if attr["tags.%"] != "0" {
return fmt.Errorf("expected 0 tags")

return nil
Expand Down Expand Up @@ -143,3 +163,57 @@ data "aws_prefix_list" "test" {

func TestAccDataSourceAwsPrefixList_managedPrefixList(t *testing.T) {
resourceName := "aws_prefix_list.test"
dataSourceName := "data.aws_prefix_list.test"

resource.ParallelTest(t, resource.TestCase{
PreCheck: func() { testAccPreCheck(t) },
Providers: testAccProviders,
CheckDestroy: testAccCheckAWSPrefixListDestroy,
Steps: []resource.TestStep{
Config: testAccDataSourceAwsPrefixListConfig_managedPrefixList,
Check: resource.ComposeTestCheckFunc(
resource.TestCheckResourceAttrPair(resourceName, "id", dataSourceName, "id"),
resource.TestCheckResourceAttrPair(resourceName, "name", dataSourceName, "name"),
resource.TestCheckResourceAttrPair(resourceName, "arn", dataSourceName, "arn"),
resource.TestCheckResourceAttrPair(resourceName, "owner_id", dataSourceName, "owner_id"),
testAccCheckResourceAttrAccountID(dataSourceName, "owner_id"),
resource.TestCheckResourceAttrPair(resourceName, "name", dataSourceName, "name"),
resource.TestCheckResourceAttrPair(resourceName, "address_family", dataSourceName, "address_family"),
resource.TestCheckResourceAttrPair(resourceName, "max_entries", dataSourceName, "max_entries"),
resource.TestCheckResourceAttr(dataSourceName, "cidr_blocks.#", "2"),
resource.TestCheckResourceAttr(dataSourceName, "cidr_blocks.0", ""),
resource.TestCheckResourceAttr(dataSourceName, "cidr_blocks.1", ""),
resource.TestCheckResourceAttr(dataSourceName, "tags.%", "2"),
resource.TestCheckResourceAttr(dataSourceName, "tags.Key1", "Value1"),
resource.TestCheckResourceAttr(dataSourceName, "tags.Key2", "Value2"),

const testAccDataSourceAwsPrefixListConfig_managedPrefixList = `
resource "aws_prefix_list" "test" {
name = "tf-test-acc"
max_entries = 5
address_family = "IPv4"
entry {
cidr_block = ""
entry {
cidr_block = ""
tags = {
Key1 = "Value1"
Key2 = "Value2"
data "aws_prefix_list" "test" {
prefix_list_id =
35 changes: 32 additions & 3 deletions website/docs/d/prefix_list.html.markdown
Original file line number Diff line number Diff line change
Expand Up @@ -8,8 +8,8 @@ description: |-

# Data Source: aws_prefix_list

`aws_prefix_list` provides details about a specific prefix list (PL)
in the current region.
`aws_prefix_list` provides details about a specific AWS prefix list (PL)
or a customer-managed prefix list in the current region.

This can be used both to validate a prefix list given in a variable
and to obtain the CIDR blocks (IP address ranges) for the associated
Expand Down Expand Up @@ -64,6 +64,30 @@ data "aws_prefix_list" "test" {

### Find a managed prefix list

resource "aws_prefix_list" "example" {
name = "example"
max_entries = 5
address_family = "IPv4"
entry {
cidr_block = ""
entry {
cidr_block = ""
tags = {
Key1 = "Value1"
Key2 = "Value2"
data "aws_prefix_list" "example" {
prefix_list_id =

## Argument Reference

The arguments of this data source act as filters for querying the available
Expand All @@ -78,13 +102,18 @@ whose data will be exported as attributes.

The following arguments are supported by the `filter` configuration block:

* `name` - (Required) The name of the filter field. Valid values can be found in the [EC2 DescribePrefixLists API Reference](
* `name` - (Required) The name of the filter field. Valid values can be found in the EC2 [DescribeManagedPrefixLists]( API Reference.
* `values` - (Required) Set of values that are accepted for the given filter field. Results will be selected if any given value matches.

## Attributes Reference

In addition to all arguments above, the following attributes are exported:

* `id` - The ID of the selected prefix list.
* `arn` - The ARN of the selected prefix list.
* `name` - The name of the selected prefix list.
* `cidr_blocks` - The list of CIDR blocks for the AWS service associated with the prefix list.
* `owner_id` - The Account ID of the owner of a customer-managed prefix list, or `AWS` otherwise.
* `address_family` - The address family of the prefix list. Valid values are `IPv4` and `IPv6`.
* `max_entries` - When then prefix list is managed, the maximum number of entries it supports, or null otherwise.
* `tags` - A map of tags assigned to the resource.

0 comments on commit ccd00bf

Please sign in to comment.